CVE-2023-27532
CISA KEVRansomwareAs of 2025-11-03, CVE-2023-27532 is a CVSS 7.5 (HIGH-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 83.6%. Threadlinqs Intelligence tracks 4 threats exploiting it.
Last updated: 2025-11-03
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
CWE-306
Exploitation status
CISA KEV-listed (known exploited)
Threats tracking this CVE
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage — HIGH
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program — CRITICAL
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026) — HIGH
- AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55 Countries Using LLM-Generated Tooling and Custom MCP Framework — CRITICAL
References
- https://www.veeam.com/kb4424
- https://www.veeam.com/kb4424
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27532
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.