Exploitation timeline
Threadlinqs has recorded 10 Veeam CVEs published between and . The busiest month was 2026-03 (8 new CVEs). 2 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 10 of 10 tracked Veeam CVEs.
- CVE-2023-27532high 7.5KEVRansomwareEPSS 83.6%
- CVE-2024-40711critical 9.8KEVRansomwareEPSS 68.2%
- CVE-2026-21708critical 9.9EPSS 1.1%
- CVE-2026-21671critical 9.1EPSS 0.3%
- CVE-2026-21666critical 9.9EPSS 0.3%
- CVE-2026-21667critical 9.9EPSS 0.3%
- CVE-2026-21669critical 9.9EPSS 0.3%
- CVE-2026-21672high 8.8EPSS 0%
- CVE-2026-21670high 7.7EPSS 0%
- CVE-2026-21668high 8.8EPSS 0%
Products affected
Threadlinqs normalises CPE and CNA product records across all 10 CVEs; 2 distinct Veeam products are affected. The most frequently affected:
- Backup & Replication 8 CVEs
- Backup and Replication 2 CVEs
Threat activity
13 tracked threat campaigns reference Veeam products or exploit Veeam CVEs:
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)HIGH
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum CryptoHIGH
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and DjangoCRITICAL
- Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prisonHIGH
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud StorageHIGH
- Spirals Ransomware: Rust-Based Double-Extortion Family Breaches South Asian IT Services Firm via IIS Web Shell in Under 24 HoursHIGH
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate ProgramCRITICAL
- Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)CRITICAL
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)HIGH
- Payload Ransomware — Babuk-Derivative ChaCha20 + Curve25519 ECDH Per-File Encryption Targeting Windows and ESXiHIGH
- Payouts King Ransomware Uses QEMU Virtual Machines to Bypass EDR and Endpoint Security ControlsHIGH
- Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708)CRITICAL
- AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55 Countries Using LLM-Generated Tooling and Custom MCP FrameworkCRITICAL
Threat actors targeting Veeam
Named threat actors attributed to campaigns that involve Veeam products or CVEs, with the number of linked campaigns:
How to prioritise Veeam patching
This order follows the data Threadlinqs holds for Veeam, not a generic severity checklist:
- 2 of 10 Veeam CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2023-27532, CVE-2024-40711.
- 2 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-21708 (1.1%), CVE-2026-21671 (0.3%), CVE-2026-21666 (0.3%).
- 6 CVEs score Critical and 4 High on CVSS v3 (maximum 9.9, average 9.1); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.