Veritas develops a focused portfolio of enterprise backup, recovery, and data governance products—including NetBackup, Enterprise Vault, and Flex appliances—that operate in privileged, data-centric roles across large organizations' infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the combination of administrative access, serialization complexity, and web-facing management interfaces that characterize backup and enterprise data-management platforms. The recurring weakness classes include deserialization of untrusted data, input-validation flaws such as cross-site scripting and SQL injection, and path-traversal conditions that recur across NetBackup and the Flex product line, exposing authentication, data-access, and system-command boundaries. Defenders should prioritize patching for Veritas products given their elevated severity profile and their control over backups and recovery operations; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Veritas over time
Signals from CVEs in this vendor scope (142 CVEs).
142 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22965CRITICAL A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run | Apr 1, 2022 | 9.8 | 98 | YES | YES |
CVE-2021-27877CRITICAL An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer | Mar 1, 2021 | 9.8 | 96 | YES | YES |
CVE-2021-27878HIGH An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a | Mar 1, 2021 | 8.8 | 85 | YES | YES |
CVE-2017-8895CRITICAL In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead | May 10, 2017 | 9.8 | 85 | NO | YES |
CVE-2021-27876HIGH An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a | Mar 1, 2021 | 8.1 | 79 | YES | YES |
CVE-2004-1389MEDIUM Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server | Dec 31, 2004 | 6.0 | 43 | NO | YES |
CVE-2017-6403CRITICAL An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password. | Mar 2, 2017 | 9.8 | 42 | NO | NO |
CVE-2026-44925HIGH Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious | May 20, 2026 | 8.8 | 35 | NO | NO |
CVE-2005-0772HIGH VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1 | Jun 28, 2005 | 7.5 | 35 | NO | NO |
CVE-2019-18780CRITICAL An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or | Nov 5, 2019 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (142 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Veritas.
Media articles that mention a CVE ID that affects a product developed by Veritas — matched by CVE ID, not by vendor name.