ZeroHour

Vulnerabilities

74 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21669
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

NVD description · AI analysis pending
9.9
group max
1%
  • veeam veeam backup \& replication
CVE-2025-55125
+3 in the same advisory: …59468 …59470 …59469
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

NVD description · AI analysis pending
9.8
group max
<1%
  • veeam veeam backup \& replication
CVE-2025-48983
+1 in the same advisory: …48984
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authen

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

NVD description · AI analysis pending
9.9
group max
<1%
  • veeam veeam backup \& replication
CVE-2025-48982
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious fi

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

NVD description · AI analysis pending
7.8<1%
  • veeam veeam agent for windows
CVE-2025-23121
+1 in the same advisory: …24286
Authenticated Domain-User RCE in Veeam Backup & Replication

CVE-2025-23121 is a code-injection vulnerability (CWE-94) in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server over the network. An attacker triggers it by sending a crafted request to the backup server's network-facing components using valid, low-privileged domain credentials, with no user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity and availability of the backup server (CVSS 3.1: 8.8 per the vector provided, though some coverage lists a 9.9 score). Any organization running Veeam Backup & Replication is affected, particularly environments where many or low-privilege domain accounts can reach the backup server. As of this writing it is not in CISA KEV and no public PoC is known, but the EPSS of 22.2% (98th percentile) indicates an elevated probability of exploitation within the next 30 days, and Veeam has shipped a fix.

Do: Upgrade Veeam Backup & Replication to the latest patched release per Veeam's security advisory for CVE-2025-23121. In the meantime, restrict which domain accounts can authenticate to the Backup Server, ensure the server is not exposed to the public internet, and audit for unusual process execution or network connections from backup infrastructure. Given the high EPSS score, prioritize patching and monitor Veeam/Kev feeds for signs of in-the-wild exploitation.

8.8
group max
22%
  • Veeam Backup & Replication (Backup Server component)
mass≈ hundreds of thousands of backup-server deployments (order of 10^5–10^6 installations)
CVE-2025-23120
Domain-User RCE via Deserialization in Veeam Backup & Replication

Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows remote code execution. Per the CVSS vector (AV:N/AC:L/PR:L/UI:N), the attack is network-reachable, straightforward to execute, and requires only low-privilege credentials — a regular domain user — with no user interaction; the vendor description states it yields RCE 'for domain users'. An attacker who obtains or already holds any domain-user account that can reach the backup server gains code execution with high confidentiality, integrity and availability impact, a foothold that is especially dangerous in backup infrastructure because those servers often hold credentials for large parts of the estate and are prime ransomware targets. Any organization running Veeam Backup & Replication is potentially affected. Veeam has released a fix (reported alongside its patch for the related CVE-2025-23121, rated 9.9, in the same product); a public technical write-up/PoC from watchTowr exists, the flaw is not yet in CISA's KEV, and EPSS assigns a 24% probability (98th percentile) of exploitation within 30 days.

Do: Upgrade Veeam Backup & Replication to the patched release specified in Veeam's security advisory; if you already applied the fix for the related CVE-2025-23121 (CVSS 9.9), verify you are on the newest build, as this flaw was disclosed alongside that patch. Restrict network access to backup infrastructure, review which domain accounts can reach the B&R server, and monitor for exploitation attempts given the public PoC and elevated EPSS score.

8.824% PoC
  • Veeam Backup & Replication
large≈ hundreds of thousands of enterprise installations (Veeam's flagship product; Veeam has publicly reported 550,000+ customers)
CVE-2025-23082
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF).

Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

NVD description · AI analysis pending
7.2<1%
  • veeam backup
CVE-2024-45207
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations.

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services

NVD description · AI analysis pending
7.0<1%
  • veeam veeam agent for windows
CVE-2024-45206
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.

NVD description · AI analysis pending
6.5<1%
  • veeam veeam service provider console
CVE-2024-40717
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs.

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.

NVD description · AI analysis pending
8.8
group max
<1%
  • veeam veeam backup \& replication
CVE-2024-40715
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass.

A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.

NVD description · AI analysis pending
7.7<1%
  • veeam veeam backup \& replication
CVE-2024-42024
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where t

A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.

NVD description · AI analysis pending
8.8
group max
1%
  • veeam one
CVE-2024-40710
+4 in the same advisory: …40714 …39718 …40713 …40712
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive info

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.

NVD description · AI analysis pending
8.8
group max
1%
  • veeam veeam backup \& replication
CVE-2024-40711
Unauthenticated Deserialization RCE in Veeam Backup & Replication

Veeam Backup & Replication contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to send a maliciously crafted serialized payload to the product's network-facing service and achieve remote code execution, with no privileges or user interaction required (CVSS 3.1: 9.8). Successful exploitation yields full code execution on the backup server with high impact on confidentiality, integrity and availability, and is especially valuable to attackers because backup infrastructure typically stores credentials and ransomware operators seek to destroy or encrypt backups before attacking production systems. Any organization running Veeam Backup & Replication is in scope; the provided data does not specify exact affected version ranges, so consult Veeam's advisory for the affected/fixed builds. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2024-10-17 with known ransomware use, a public proof-of-concept has been published by watchTowr, EPSS estimates a 90.4% probability of exploitation within 30 days (100th percentile), and the exploit has been reused in Frag ransomware attacks.

Do: Apply Veeam's security updates immediately (the vendor released fixes for 18 flaws, including 5 critical ones); per the KEV required action, apply mitigations per Veeam's instructions or discontinue use if mitigations are unavailable. Until patched, restrict network access to the backup server from untrusted networks and remove unnecessary internet exposure. Given confirmed ransomware exploitation, also hunt for signs of compromise on backup servers and review backup job integrity and stored credentials.

9.890% KEV ransomware PoC
  • Veeam Backup & Replication
mass≈ hundreds of thousands of on-prem backup server deployments plausibly affected (tens of thousands internet-exposed)
CVE-2024-29855
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

NVD description · AI analysis pending
9.022%
  • veeam recovery orchestrator
CVE-2024-29853
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.

An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.

NVD description · AI analysis pending
7.8<1%
  • veeam veeam agent for windows
CVE-2024-29849
+3 in the same advisory: …29850 …29851 …29852
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

NVD description · AI analysis pending
9.8
group max
38%
  • veeam veeam backup \& replication
CVE-2024-29212
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its component

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

NVD description · AI analysis pending
9.92%
  • veeam veeam service provider console
CVE-2024-22022
Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service accou

Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.

NVD description · AI analysis pending
8.8<1%
  • veeam recovery orchestrator
CVE-2024-22021
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the on

Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.

NVD description · AI analysis pending
4.3<1%
  • veeam availability orchestrator
  • veeam disaster recovery orchestrator
  • veeam recovery orchestrator