Veeam vulnerabilities
5 CVEs tracked
Veeam appears in our reporting both as a direct target for ransomware groups and in the context of critical software vulnerabilities. Key incidents include Lynx ransomware actors using the Veeam Backup & Replication console to remove backups from the configuration database, and threat actors with existing Domain Admin privileges extracting credentials from the PostgreSQL database using encoded PowerShell and DPAPI decryption logic. Defenders should prioritize immediate patching for the Veeam Service Provider Console vulnerabilities CVE-2026-58071, CVE-2026-58072, CVE-2026-58073 (which can lead to unauthenticated agent credential theft, arbitrary file write, and RCE) and CVE-2026-56844, a local privilege escalation flaw in the Veeam Updater component.
Azərbaycanca: Veeam hesabatlarımızda həm ransomware qruplarının birbaşa hədəfi, həm də kritik proqram təminatı zəiflikləri kontekstində görünür. Əsas hadisələrə Lynx ransomware-nin Veeam Backup & Replication konsolu vasitəsilə ehtiyat nüsxələri konfiqurasiya bazasından silməsi və artıq Domain Admin hüquqlarına malik təhlükə aktorunun PostgreSQL verilənlər bazasından etimadnamələri çıxarmaq üçün kodlaşdırılmış PowerShell və DPAPI decrypt məntiqindən istifadə etməsi daxildir. Müdafiəçilər Veeam Service Provider Console üçün CVE-2026-58071, CVE-2026-58072, CVE-2026-58073 (təsdiqlənməmiş agent etimadnaməsinin oğurlanmasına, ixtiyari fayl yazılmasına və RCE-yə səbəb ola bilər) və Veeam Updater üçün yerli imtiyaz artımına səbəb olan CVE-2026-56844 zəifliklərinin dərhal patchnaməsini prioritetləşdirməlidir.
This vendor's CVEs5
This hub is built from skopnix's own reporting on Veeam: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.