veeam has 5 CVEs on record. The busiest recent month was January 2026 with 4. The median CVSS is 9.0 (critical), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-77 (3). Most affected products: veeam_backup_&_replication (4), Backup and Replication (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.0
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Products
- veeam_backup_&_replication 4
- Backup and Replication 1
Worst active — by depth score
CVE-2025-59470Critical· 9.0This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.62CVE-2026-32996High· 7.3This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.52CVE-2025-59469Critical· 9.0This vulnerability allows a Backup or Tape Operator to write files as root.50CVE-2025-59468Critical· 9.0This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.50CVE-2025-55125High· 7.8This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.43
veeam vulnerabilities
CVEs affecting veeam, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-32996High· 7.3PoCThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
CVE-2025-59470Critical· 9.0PoCThis vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVE-2025-59469Critical· 9.0This vulnerability allows a Backup or Tape Operator to write files as root.
This vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2025-59468Critical· 9.0This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
CVE-2025-55125High· 7.8This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.