<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/categories/stockage-sauvegarde.xml</id>
  <title>Exploit Radar: Backup, storage and NAS</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities in the “Backup, storage and NAS” category (indicative classification).</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/categories/stockage-sauvegarde.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/produits/stockage-sauvegarde/"/>
  <updated>2026-09-16T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-87886/</id>
    <title>CVE-2026-87886 — Acronis Backup</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-87886/"/>
    <updated>2026-09-16T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Acronis; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 16, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-22769/</id>
    <title>CVE-2026-22769 — Dell RecoverPoint</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-22769/"/>
    <updated>2026-02-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Dell; if none are available, stop using the product. For cloud services, follow the guidance from Dell. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on February 18, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-34028/</id>
    <title>CVE-2025-34028 — Commvault Command Center</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-34028/"/>
    <updated>2025-05-02T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Commvault; if none are available, stop using the product. For cloud services, follow the guidance from Commvault. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 2, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-3928/</id>
    <title>CVE-2025-3928 — Commvault Web Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-3928/"/>
    <updated>2025-04-28T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Commvault; if none are available, stop using the product. For cloud services, follow the guidance from Commvault. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 28, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-1976/</id>
    <title>CVE-2025-1976 — Brocade Fabric OS (FOS)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-1976/"/>
    <updated>2025-04-28T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Brocade; if none are available, stop using the product. For cloud services, follow the guidance from Brocade. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 28, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-48248/</id>
    <title>CVE-2024-48248 — NAKIVO Backup and Replication</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-48248/"/>
    <updated>2025-03-19T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from NAKIVO; if none are available, stop using the product. For cloud services, follow the guidance from NAKIVO. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 19, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-40711/</id>
    <title>CVE-2024-40711 — Veeam Backup &amp; Replication</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-40711/"/>
    <updated>2024-10-17T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Veeam; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on October 17, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-45249/</id>
    <title>CVE-2023-45249 — Acronis Cyber Infrastructure (ACI)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-45249/"/>
    <updated>2024-07-29T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Acronis; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 29, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-3272/</id>
    <title>CVE-2024-3272 — D-Link NAS DNS (ShareCenter)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-3272/"/>
    <updated>2024-04-11T00:00:00Z</updated>
    <summary type="text">This product has reached end of life: no patch is coming. Remove it or isolate it from the network. CISA deadline: 21 days. End of life: remove it. Added to CISA’s catalog of exploited vulnerabilities on April 11, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-3273/</id>
    <title>CVE-2024-3273 — D-Link NAS DNS (ShareCenter)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-3273/"/>
    <updated>2024-04-11T00:00:00Z</updated>
    <summary type="text">This product has reached end of life: no patch is coming. Remove it or isolate it from the network. CISA deadline: 21 days. End of life: remove it. Added to CISA’s catalog of exploited vulnerabilities on April 11, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-28434/</id>
    <title>CVE-2023-28434 — MinIO</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-28434/"/>
    <updated>2023-09-19T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from MinIO; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on September 19, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-27532/</id>
    <title>CVE-2023-27532 — Veeam Backup &amp; Replication</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-27532/"/>
    <updated>2023-08-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Veeam; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on August 22, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-27992/</id>
    <title>CVE-2023-27992 — Zyxel NAS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-27992/"/>
    <updated>2023-06-23T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 23, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-28432/</id>
    <title>CVE-2023-28432 — MinIO</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-28432/"/>
    <updated>2023-04-21T00:00:00Z</updated>
    <summary type="text">Apply the security update from MinIO. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 21, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-27877/</id>
    <title>CVE-2021-27877 — Veritas Backup Exec</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-27877/"/>
    <updated>2023-04-07T00:00:00Z</updated>
    <summary type="text">Apply the security update from Veritas. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-27878/</id>
    <title>CVE-2021-27878 — Veritas Backup Exec</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-27878/"/>
    <updated>2023-04-07T00:00:00Z</updated>
    <summary type="text">Apply the security update from Veritas. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-27876/</id>
    <title>CVE-2021-27876 — Veritas Backup Exec</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-27876/"/>
    <updated>2023-04-07T00:00:00Z</updated>
    <summary type="text">Apply the security update from Veritas. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on April 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-24990/</id>
    <title>CVE-2022-24990 — TerraMaster OS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-24990/"/>
    <updated>2023-02-10T00:00:00Z</updated>
    <summary type="text">Apply the security update from TerraMaster. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on February 10, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-26501/</id>
    <title>CVE-2022-26501 — Veeam Backup &amp; Replication</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-26501/"/>
    <updated>2022-12-13T00:00:00Z</updated>
    <summary type="text">Apply the security update from Veeam. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on December 13, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-26500/</id>
    <title>CVE-2022-26500 — Veeam Backup &amp; Replication</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-26500/"/>
    <updated>2022-12-13T00:00:00Z</updated>
    <summary type="text">Apply the security update from Veeam. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on December 13, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-27593/</id>
    <title>CVE-2022-27593 — QNAP Photo Station</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-27593/"/>
    <updated>2022-09-08T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on September 8, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-7192/</id>
    <title>CVE-2019-7192 — QNAP Photo Station</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-7192/"/>
    <updated>2022-06-08T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 8, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-7193/</id>
    <title>CVE-2019-7193 — QNAP NAS (QTS / QuTS hero)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-7193/"/>
    <updated>2022-06-08T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 8, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-7194/</id>
    <title>CVE-2019-7194 — QNAP Photo Station</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-7194/"/>
    <updated>2022-06-08T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 8, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-7195/</id>
    <title>CVE-2019-7195 — QNAP Photo Station</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-7195/"/>
    <updated>2022-06-08T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on June 8, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-19949/</id>
    <title>CVE-2018-19949 — QNAP NAS (QTS / QuTS hero)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-19949/"/>
    <updated>2022-05-24T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 24, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-19953/</id>
    <title>CVE-2018-19953 — QNAP NAS (QTS / QuTS hero)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-19953/"/>
    <updated>2022-05-24T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 24, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-19943/</id>
    <title>CVE-2018-19943 — QNAP NAS (QTS / QuTS hero)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-19943/"/>
    <updated>2022-05-24T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on May 24, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-16057/</id>
    <title>CVE-2019-16057 — D-Link NAS DNS (ShareCenter)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-16057/"/>
    <updated>2022-04-15T00:00:00Z</updated>
    <summary type="text">This product has reached end of life: no patch is coming. Remove it or isolate it from the network. CISA deadline: 21 days. Used in ransomware campaigns. End of life: remove it. Added to CISA’s catalog of exploited vulnerabilities on April 15, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-2509/</id>
    <title>CVE-2020-2509 — QNAP NAS (QTS / QuTS hero)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-2509/"/>
    <updated>2022-04-11T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on April 11, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-28799/</id>
    <title>CVE-2021-28799 — QNAP NAS (QTS / QuTS hero)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-28799/"/>
    <updated>2022-03-31T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on March 31, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2018-14839/</id>
    <title>CVE-2018-14839 — LG N1A1 NAS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2018-14839/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from LG. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-2506/</id>
    <title>CVE-2020-2506 — QNAP Helpdesk</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-2506/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from QNAP. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-9054/</id>
    <title>CVE-2020-9054 — Zyxel NAS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-9054/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2015-4068/</id>
    <title>CVE-2015-4068 — Arcserve Unified Data Protection (UDP)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2015-4068/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Arcserve. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-25506/</id>
    <title>CVE-2020-25506 — D-Link NAS DNS (ShareCenter)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-25506/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from D-Link. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-5847/</id>
    <title>CVE-2020-5847 — Unraid</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-5847/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Unraid. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-5849/</id>
    <title>CVE-2020-5849 — Unraid</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-5849/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Unraid. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
