Veeam 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
一般的な弱点パターンには vendor risk cross-site scripting、vendor risk xxe、vendor risk ssrf, and vendor risk csrf があり、vendor surface production workloads and vendor surface software deployment の利用場面で ファイル上書き and vendor impact session compromise などのリスクが生じる可能性があります。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2026-21671 | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. | [email protected] | 9.1 | 0.16% | 2026-03-12 | 2026-05-10 |
| CVE-2026-21670 | A vulnerability allowing a low-privileged user to extract saved SSH credentials. | [email protected] | 7.7 | 0.03% | 2026-03-12 | 2026-05-10 |
| CVE-2026-21669 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | [email protected] | 9.9 | 0.45% | 2026-03-12 | 2026-05-10 |
| CVE-2026-21668 | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. | [email protected] | 8.8 | 0.04% | 2026-03-12 | 2026-05-10 |
| CVE-2026-21667 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | [email protected] | 9.9 | 0.40% | 2026-03-12 | 2026-03-31 |
| CVE-2026-21666 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | [email protected] | 9.9 | 0.40% | 2026-03-12 | 2026-03-31 |
| CVE-2025-59470 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. | [email protected] | 9.0 | 0.12% | 2026-01-08 | 2026-01-14 |
| CVE-2025-59469 | This vulnerability allows a Backup or Tape Operator to write files as root. | [email protected] | 9.0 | 0.02% | 2026-01-08 | 2026-01-14 |
| CVE-2025-59468 | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter. | [email protected] | 9.0 | 0.11% | 2026-01-08 | 2026-01-14 |
| CVE-2025-55125 | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. | [email protected] | 7.8 | 0.07% | 2026-01-08 | 2026-01-12 |
| CVE-2025-48984 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. | [email protected] | 8.8 | 0.31% | 2025-10-31 | 2025-11-11 |
| CVE-2025-48983 | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user. | [email protected] | 9.9 | 0.25% | 2025-10-31 | 2025-12-01 |
| CVE-2025-48982 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file. | [email protected] | 7.8 | 0.05% | 2025-10-31 | 2025-12-01 |
| CVE-2025-24286 | A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. | [email protected] | 7.2 | 0.26% | 2025-06-19 | 2025-07-16 |
| CVE-2025-23121 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user | [email protected] | 8.8 | 1.31% | 2025-06-19 | 2025-07-15 |
| CVE-2025-23120 | A vulnerability allowing remote code execution (RCE) for domain users. | [email protected] | 8.8 | 41.32% | 2025-03-20 | 2025-04-02 |
| CVE-2025-23082 | Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | [email protected] | 7.2 | 0.49% | 2025-01-14 | 2025-11-18 |
| CVE-2024-45207 | DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services | [email protected] | 7.0 | 0.13% | 2024-12-04 | 2025-07-02 |
| CVE-2024-45206 | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. | [email protected] | 6.5 | 0.40% | 2024-12-04 | 2025-07-02 |
| CVE-2024-45204 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader security vulnerabilities. | [email protected] | 4.3 | 0.16% | 2024-12-04 | 2025-04-24 |