Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Veeam

First CVE: Oct 16, 2015Active for: 11 yearsTotal CVEs: 75
73.6
VTI Score
TOP TARGET

Veeam is a specialist vendor in backup, replication, and disaster-recovery software deployed across enterprise data centers and hybrid-cloud environments, where its products sit at a critical juncture between production workloads and recovery infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and have an elevated tendency toward confirmed in-the-wild exploitation and public exploit availability, reflecting the high-value nature of backup and orchestration targets. The exposure concentrates in flagship products such as Backup & Replication, Veeam One, and Recovery Orchestrator, and recurs through weakness classes including deserialization of untrusted data, improper access control, sensitive-information exposure, and cross-site scripting—patterns that reflect both the integration-heavy architecture of enterprise backup platforms and their role as trusted conduits for administrative access. Defenders should prioritize inventory and patching of Veeam deployments, especially internet-reachable instances, and treat recovery-tier compromises as high-impact; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
75
Total CVEs
More Total CVEs than 99% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
5.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Veeam over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2015
10 years ago
Most Recent CVE
Mar 12, 2026
134 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-40711CRITICAL
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Sep 7, 20249.897YESYES
CVE-2023-27532HIGH
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backu
Mar 10, 20237.593YESNO
CVE-2020-10915CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnera
Apr 22, 20209.880NOYES
CVE-2022-26501CRITICAL
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Mar 17, 20229.873YESNO
CVE-2022-26500HIGH
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers
Mar 17, 20228.869YESNO
CVE-2020-10914CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnera
Apr 22, 20209.860NOYES
CVE-2020-15419HIGH
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit t
Jul 28, 20207.550NONO
CVE-2025-23120HIGH
A vulnerability allowing remote code execution (RCE) for domain users.
Mar 20, 20258.842NONO
CVE-2024-29849CRITICAL
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
May 22, 20249.841NONO
CVE-2023-38547CRITICAL
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead t
Nov 7, 20239.841NONO
View all 75 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products75 CVEs
23%
48%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (8.0%)
Network68 (90.7%)
Unknown1 (1.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low68 (90.7%)
High6 (8.0%)
Unknown1 (1.3%)
User Interaction
None64 (85.3%)
Unknown1 (1.3%)
Required10 (13.3%)
Privileges Required
Low45 (60.0%)
High7 (9.3%)
None22 (29.3%)
Unknown1 (1.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (75 CVEs).

CISA KEV
4 CVEs
5.3% of CVEs· 99th percentile
Metasploit
2 CVEs
2.7% of CVEs· 97th percentile
Nuclei
1 CVE
1.3% of CVEs· 95th percentile
ExploitDB
1 CVE
1.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Veeam.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Veeam — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Veeam's Products

View all 3 CNAs →

Top CWEs