Vendor
Veeam
As of , 4 Veeam vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2024-40711.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2024-40711Backup and Replication Deserialization | Veeam Backup & Replication | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 2 | CVE-2023-27532Cloud Connect Missing Authentication for Critical Function | Veeam Backup & Replication | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 3 | CVE-2022-26500Remote Code Execution | Veeam Backup & Replication | Patch this weekRansomware use | 0.06 | ||
| 4 | CVE-2022-26501Remote Code Execution | Veeam Backup & Replication | Patch this weekRansomware use | 0.04 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2022 | 2 |
| 2023 | 1 |
| 2024 | 1 |
| 2025 | none |
| 2026 | none |