| CVE-2026-65641 | medium | — | A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the s… | Aug 26, 2026 | Aug 27, 2026 |
| CVE-2026-64632 | medium | — | A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter servi… | Aug 26, 2026 | Sep 3, 2026 |
| CVE-2026-58070 | medium | — | A vulnerability that records guest OS processing credentials in cleartext in a support log on the gu… | Aug 26, 2026 | Sep 3, 2026 |
| CVE-2026-64634 | medium | — | A vulnerability allowing local privilege escalation to the Reporter service context. | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-64633 | medium | — | A vulnerability allowing remote unauthenticated code execution on the agent host. | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-64631 | medium | — | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-64630 | medium | — | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared… | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-58075 | medium | — | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which ca… | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-58074 | medium | — | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-58073 | medium | — | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonat… | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-58072 | medium | — | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management se… | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-58071 | medium | — | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the… | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-58067 | medium | — | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust ho… | Aug 4, 2026 | Sep 3, 2026 |
| CVE-2026-64635 | medium | 5.3 | Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provid… | Jul 30, 2026 | Sep 3, 2026 |
| CVE-2026-56844 | high | 8.4 | A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a lo… | Jul 22, 2026 | Jul 22, 2026 |
| CVE-2026-44963 | critical | 9.4 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain… | Jun 9, 2026 | Jun 10, 2026 |
| CVE-2026-32998 | critical | 9.4 | This vulnerability in Veeam Service Provider Console allows for remote code execution. | May 28, 2026 | May 29, 2026 |
| CVE-2026-32997 | high | 8.6 | A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary… | May 28, 2026 | May 29, 2026 |
| CVE-2026-32996 | high | 7.3 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. | May 28, 2026 | May 29, 2026 |
| CVE-2026-21708 | critical | 9.9 | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user… | Mar 12, 2026 | Jun 5, 2026 |
| CVE-2026-21672 | high | 8.8 | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication serv… | Mar 12, 2026 | Mar 13, 2026 |
| CVE-2026-21671 | critical | 9.1 | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote … | Mar 12, 2026 | May 10, 2026 |
| CVE-2026-21670 | high | 7.7 | A vulnerability allowing a low-privileged user to extract saved SSH credentials. | Mar 12, 2026 | May 10, 2026 |
| CVE-2026-21669 | critical | 9.9 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the … | Mar 12, 2026 | May 10, 2026 |
| CVE-2026-21668 | high | 8.8 | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrar… | Mar 12, 2026 | May 10, 2026 |