Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Veritas

First CVE: Dec 31, 2003Active for: 23 yearsTotal CVEs: 142
60.7
VTI Score
TOP TARGET

Veritas develops a focused portfolio of enterprise backup, recovery, and data governance products—including NetBackup, Enterprise Vault, and Flex appliances—that operate in privileged, data-centric roles across large organizations' infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the combination of administrative access, serialization complexity, and web-facing management interfaces that characterize backup and enterprise data-management platforms. The recurring weakness classes include deserialization of untrusted data, input-validation flaws such as cross-site scripting and SQL injection, and path-traversal conditions that recur across NetBackup and the Flex product line, exposing authentication, data-access, and system-command boundaries. Defenders should prioritize patching for Veritas products given their elevated severity profile and their control over backups and recovery operations; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
142
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
2.8%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Veritas over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
May 20, 2026
65 days ago

Products(31 total)

Top CVEs

Signals from CVEs in this vendor scope (142 CVEs).

142 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-22965CRITICAL
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run
Apr 1, 20229.898YESYES
CVE-2021-27877CRITICAL
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer
Mar 1, 20219.896YESYES
CVE-2021-27878HIGH
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a
Mar 1, 20218.885YESYES
CVE-2017-8895CRITICAL
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead
May 10, 20179.885NOYES
CVE-2021-27876HIGH
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a
Mar 1, 20218.179YESYES
CVE-2004-1389MEDIUM
Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server
Dec 31, 20046.043NOYES
CVE-2017-6403CRITICAL
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.
Mar 2, 20179.842NONO
CVE-2026-44925HIGH
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious
May 20, 20268.835NONO
CVE-2005-0772HIGH
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1
Jun 28, 20057.535NONO
CVE-2019-18780CRITICAL
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or
Nov 5, 20199.833NONO
View all 142 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products142 CVEs
27%
44%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local29 (20.4%)
Network106 (74.6%)
Unknown5 (3.5%)
Physical0 (0.0%)
Adjacent Network2 (1.4%)
Attack Complexity
Low133 (93.7%)
High4 (2.8%)
Unknown5 (3.5%)
User Interaction
None123 (86.6%)
Unknown5 (3.5%)
Required14 (9.9%)
Privileges Required
Low65 (45.8%)
High12 (8.5%)
None60 (42.3%)
Unknown5 (3.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (142 CVEs).

CISA KEV
4 CVEs
2.8% of CVEs· 99th percentile
Metasploit
6 CVEs
4.2% of CVEs· 98th percentile
Nuclei
2 CVEs
1.4% of CVEs· 95th percentile
ExploitDB
2 CVEs
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Veritas.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Veritas — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Veritas's Products

View all 3 CNAs →

Top CWEs