Veeam released security updates for multiple products, including Backup & Replication, Service Provider Console, Veeam ONE, Agent for Linux, and several backup plug-ins, to fix a set of critical and high-severity vulnerabilities. The most severe issue, CVE-2024-40711, is a critical unauthenticated remote code execution flaw in Veeam Backup & Replication with a CVSS 9.8 rating, allowing attackers to potentially compromise backup servers without logging in.
The broader patch set also addresses weaknesses that could enable credential theft, backup manipulation, MFA bypass, privilege escalation, SSRF exploitation, and additional remote code execution in other Veeam components. Security advisories urged organizations to upgrade immediately to fixed versions, warning that backup infrastructure is a high-value target and that successful exploitation could materially increase ransomware risk by giving attackers access to recovery systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Veeam issued security bulletin KB4649 covering multiple vulnerabilities across its products, including the critical CVE-2024-40711 unauthenticated remote code execution flaw in Veeam Backup & Replication. The bulletin provided patched versions and remediation guidance for affected products.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.