VulnSea

veeam has 5 CVEs on record. The busiest recent month was January 2026 with 4. The median CVSS is 9.0 (critical), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-77 (3). Most affected products: veeam_backup_&_replication (4), Backup and Replication (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
9.0
Publish → KEV
—
Last 90 days
0 prev 1

Products

  • veeam_backup_&_replication 4
  • Backup and Replication 1
5
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

veeam vulnerabilities

CVEs affecting veeam, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-32996High· 7.3PoC
4mo ago

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

▾ MidnightVeeam · Backup and ReplicationEPSS 0.17%via NVD
CVE-2025-59470Critical· 9.0PoC
8mo ago

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

▾ Abyssalveeam · veeam_backup_&_replicationEPSS 1.6%via NVD
CVE-2025-59469Critical· 9.0
8mo ago

This vulnerability allows a Backup or Tape Operator to write files as root.

This vulnerability allows a Backup or Tape Operator to write files as root.

▾ Midnightveeam · veeam_backup_&_replicationEPSS 0.64%via NVD
CVE-2025-59468Critical· 9.0
8mo ago

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

▾ Midnightveeam · veeam_backup_&_replicationEPSS 1.2%via NVD
CVE-2025-55125High· 7.8
8mo ago

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

▾ Twilightveeam · veeam_backup_&_replicationEPSS 0.88%via NVD
veeam vulnerabilities (CVEs) · VulnSea