# Veeam vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 10 Veeam CVEs, 2 in the CISA Known Exploited Vulnerabilities catalog, 2 used in ransomware campaigns, linked to 13 tracked threat campaigns and 11 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 10 Veeam CVEs published between 2023-03-15 and 2026-03-15. The busiest month was 2026-03 (8 new CVEs). 2 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 10 of 10 tracked Veeam CVEs.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532) — HIGH 7.5 · KEV · Ransomware · EPSS 83.6% · 2023-03-10
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711) — CRITICAL 9.8 · KEV · Ransomware · EPSS 68.2% · 2024-09-07
- [CVE-2026-21708](https://intel.threadlinqs.com/cve/CVE-2026-21708) — CRITICAL 9.9 · EPSS 1.1% · 2026-03-12
- [CVE-2026-21671](https://intel.threadlinqs.com/cve/CVE-2026-21671) — CRITICAL 9.1 · EPSS 0.3% · 2026-03-12
- [CVE-2026-21666](https://intel.threadlinqs.com/cve/CVE-2026-21666) — CRITICAL 9.9 · EPSS 0.3% · 2026-03-12
- [CVE-2026-21667](https://intel.threadlinqs.com/cve/CVE-2026-21667) — CRITICAL 9.9 · EPSS 0.3% · 2026-03-12
- [CVE-2026-21669](https://intel.threadlinqs.com/cve/CVE-2026-21669) — CRITICAL 9.9 · EPSS 0.3% · 2026-03-12
- [CVE-2026-21672](https://intel.threadlinqs.com/cve/CVE-2026-21672) — HIGH 8.8 · EPSS 0% · 2026-03-12
- [CVE-2026-21670](https://intel.threadlinqs.com/cve/CVE-2026-21670) — HIGH 7.7 · EPSS 0% · 2026-03-12
- [CVE-2026-21668](https://intel.threadlinqs.com/cve/CVE-2026-21668) — HIGH 8.8 · EPSS 0% · 2026-03-12

## Products affected

Threadlinqs normalises CPE and CNA product records across all 10 CVEs; 2 distinct Veeam products are affected. The most frequently affected:

- Backup & Replication — 8 CVEs
- Backup and Replication — 2 CVEs

## Threat activity

13 tracked threat campaigns reference Veeam products or exploit Veeam CVEs:

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH — 2026-10-03
- [Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum Crypto](https://intel.threadlinqs.com/threat/TL-2026-2310) — HIGH — 2026-09-03
- [August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django](https://intel.threadlinqs.com/threat/TL-2026-1891) — CRITICAL — 2026-08-05
- [Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison](https://intel.threadlinqs.com/threat/TL-2026-1902) — HIGH — 2026-08-05
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — HIGH — 2026-07-26
- [Spirals Ransomware: Rust-Based Double-Extortion Family Breaches South Asian IT Services Firm via IIS Web Shell in Under 24 Hours](https://intel.threadlinqs.com/threat/TL-2026-1410) — HIGH — 2026-07-16
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program](https://intel.threadlinqs.com/threat/TL-2026-1138) — CRITICAL — 2026-07-06
- [Bumblebee and AdaptixC2 Deliver Akira Ransomware via Bing SEO Poisoning (TB36726/PR40373)](https://intel.threadlinqs.com/threat/TL-2026-1135) — CRITICAL — 2026-06-29
- [Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0610) — HIGH — 2026-05-27
- [Payload Ransomware — Babuk-Derivative ChaCha20 + Curve25519 ECDH Per-File Encryption Targeting Windows and ESXi](https://intel.threadlinqs.com/threat/TL-2026-0587) — HIGH — 2026-05-26
- [Payouts King Ransomware Uses QEMU Virtual Machines to Bypass EDR and Endpoint Security Controls](https://intel.threadlinqs.com/threat/TL-2026-0390) — HIGH — 2026-04-19
- [Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708)](https://intel.threadlinqs.com/threat/TL-2026-0232) — CRITICAL — 2026-03-15
- [AI-Augmented FortiGate Mass Exploitation — Russian-Speaking Actor Breaches 600+ Firewalls Across 55 Countries Using LLM-Generated Tooling and Custom MCP Framework](https://intel.threadlinqs.com/threat/TL-2026-0131) — CRITICAL — 2026-02-22

## Threat actors targeting Veeam

Named threat actors attributed to campaigns that involve Veeam products or CVEs, with the number of linked campaigns:

- [Akira](https://intel.threadlinqs.com/actor/Akira) — 4 campaigns
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 3 campaigns
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1 campaign
- [BlackBasta](https://intel.threadlinqs.com/actor/BlackBasta) — 1 campaign
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1 campaign
- [CUBA](https://intel.threadlinqs.com/actor/CUBA) — 1 campaign
- [FIN7](https://intel.threadlinqs.com/actor/FIN7) — 1 campaign
- [Interlock](https://intel.threadlinqs.com/actor/Interlock) — 1 campaign
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 1 campaign
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1 campaign
- [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) — 1 campaign

## How to prioritise Veeam patching

This order follows the data Threadlinqs holds for Veeam, not a generic severity checklist:

- 2 of 10 Veeam CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532), [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711).
- 2 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-21708](https://intel.threadlinqs.com/cve/CVE-2026-21708) (1.1%), [CVE-2026-21671](https://intel.threadlinqs.com/cve/CVE-2026-21671) (0.3%), [CVE-2026-21666](https://intel.threadlinqs.com/cve/CVE-2026-21666) (0.3%).
- 6 CVEs score Critical and 4 High on CVSS v3 (maximum 9.9, average 9.1); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/veeam
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
