CVE-2024-40711: Veeam Backup and Replication Deserialization Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-10-17. EPSS: 90.4% chance of exploitation in the next 30 days.
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Affected products
- Veeam Veeam Backup & Replication: from 12.0.0.1420, before 12.2.0.334 (fixed in 12.2.0.334)
Published 2024-09-07. Last modified 2026-06-17.