Vendor

Veeam

As of , 4 Veeam vulnerabilities are on CISA's list of exploited vulnerabilities, 4 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2024-40711.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-40711Backup and Replication DeserializationVeeam Backup & ReplicationPatch this weekRansomware use; EPSS 0.900.90
2CVE-2023-27532Cloud Connect Missing Authentication for Critical FunctionVeeam Backup & ReplicationPatch this weekRansomware use; EPSS 0.810.81
3CVE-2022-26500Remote Code ExecutionVeeam Backup & ReplicationPatch this weekRansomware use0.06
4CVE-2022-26501Remote Code ExecutionVeeam Backup & ReplicationPatch this weekRansomware use0.04

Added each year

0.511.522022: 2220222023: 1120232024: 1120242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20222
20231
20241
2025none
2026none

Used in ransomware