SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Security Updates from Veeam: 18 Vulnerabilities Addressed, Including 5 Critical Threats

Security Updates from Veeam: 18 Vulnerabilities Addressed, Including 5 Critical Threats

Sep 5, 2024By Muqsit Mamdu3 min read

Veeam has recently released critical security updates addressing a total of 18 vulnerabilities across its software products, with five of these flaws classified as critical due to their potential for remote code execution (RCE). This update is particularly significant as it targets widely used products such as Veeam Backup & Replication, Veeam ONE, and the Veeam Service Provider Console.

Remediate all critical vulnerabilities with a patch management tool. 

Understanding the Vulnerabilities

The most severe vulnerabilities identified in the September 2024 security bulletin include:

CVE-2024-40711 (CVSS score: 9.8): This critical flaw in Veeam Backup & Replication allows unauthenticated remote code execution, posing a severe risk to users who have not updated their software.

CVE-2024-42024 (CVSS score: 9.1): Found in Veeam ONE, this vulnerability enables an attacker with the Agent service account credentials to execute code remotely on the affected machine.

CVE-2024-42019 (CVSS score: 9.0): Also affecting Veeam ONE, this flaw allows attackers to access the NTLM hash of the Veeam Reporter Service account.

CVE-2024-38650 (CVSS score: 9.9): This vulnerability in the Veeam Service Provider Console permits low-privileged attackers to access the NTLM hash of the service account on the server.

CVE-2024-39714 (CVSS score: 9.9): Another critical issue in the Veeam Service Provider Console that allows low-privileged users to upload arbitrary files to the server, leading to potential remote code execution.

In addition to these critical vulnerabilities, the updates also address 13 other high-severity flaws that could lead to privilege escalation, multi-factor authentication (MFA) bypass, and elevated code execution permissions.

Mitigations and Recommendations

To protect against these vulnerabilities, users are strongly advised to update to the latest version of the affected products, which include:

Veeam Backup & Replication: Version 12.2 (build 12.2.0.334)

Veeam Agent for Linux: Version 6.2 (build 6.2.0.101)

Veeam ONE: Version 12.2 (build 12.2.0.4093)

Veeam Service Provider Console: Version 8.1 (build 8.1.0.21377)

Veeam Backup for Nutanix AHV Plug-In: Version 12.6.0.632

Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization Plug-In: Version 12.5.0.299

Given the critical nature of these vulnerabilities, particularly in the context of ransomware threats, timely updates are essential for safeguarding data protection solutions and preventing potential exploitation by threat actors.

Conclusion

The swift release of these security updates by Veeam highlights the ongoing need for vigilance in software security. Users must prioritize updating their systems to mitigate risks associated with these vulnerabilities. Regular updates and proactive security measures are vital in maintaining the integrity of data protection solutions and defending against emerging cyber threats.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026