veeam
Cloud & SaaScommercial
Latest CVEs
The 15 most recently published vulnerabilities affecting veeam.
- CVE-2026-64632A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
- CVE-2026-58070A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
- CVE-2026-65641A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
- CVE-2026-64631A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
- CVE-2026-64634A vulnerability allowing local privilege escalation to the Reporter service context.
- CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host.
- CVE-2026-64630A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
- CVE-2026-58071A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator sessio...
- CVE-2026-58067A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
- CVE-2026-58072A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.
- CVE-2026-58074A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
- CVE-2026-58075A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
- CVE-2026-58073A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
- CVE-2026-64635Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password res...5.3
- CVE-2026-56844A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.