Skip to content

Products › IT administration and security

IT administration and security

Backup, storage and NAS

Backup software, network-attached storage (NAS) and storage arrays: prime ransomware targets.

For example: Veeam, Veritas, QNAP, Commvault.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    Acronis BackupCVE-2026-87886

    Acronis Backup Incorrect Default Permissions Vulnerability

    Recently addedHunt for compromise (CISA)

    CVSS severity 7.8high

    Added Sep 16, 2026

  2. Rank 2

    Dell RecoverPointCVE-2026-22769

    Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

    CVSS severity 10.0critical

    Added Feb 18, 2026

  3. Rank 3

    Commvault Command CenterCVE-2025-34028

    Commvault Command Center Path Traversal Vulnerability

    CVSS severity 10.0critical

    Added May 2, 2025

  4. Rank 4

    Veeam Backup & ReplicationCVE-2024-40711

    Veeam Backup and Replication Deserialization Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Oct 17, 2024

  5. Rank 5

    Acronis Cyber Infrastructure (ACI)CVE-2023-45249

    Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

    CVSS severity 9.8critical

    Added Jul 29, 2024

  6. Rank 6

    Zyxel NASCVE-2023-27992

    Zyxel Multiple NAS Devices Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Jun 23, 2023

  7. Rank 7

    Veritas Backup ExecCVE-2021-27877

    Veritas Backup Exec Agent Improper Authentication Vulnerability

    RansomwareCVE from 2021, added in 2023

    CVSS severity 9.8critical

    Added Apr 7, 2023

  8. Rank 8

    Veeam Backup & ReplicationCVE-2022-26501

    Veeam Backup & Replication Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Dec 13, 2022

  9. Rank 9

    QNAP Photo StationCVE-2019-7192

    QNAP Photo Station Improper Access Control Vulnerability

    RansomwareCVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Jun 8, 2022

  10. Rank 10

    QNAP NAS (QTS / QuTS hero)CVE-2019-7193

    QNAP QTS Improper Input Validation Vulnerability

    RansomwareCVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Jun 8, 2022

Show 25 more vulnerabilities
  1. Rank 11

    QNAP Photo StationCVE-2019-7194

    QNAP Photo Station Path Traversal Vulnerability

    RansomwareCVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Jun 8, 2022

  2. Rank 12

    QNAP Photo StationCVE-2019-7195

    QNAP Photo Station Path Traversal Vulnerability

    RansomwareCVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Jun 8, 2022

  3. Rank 13

    QNAP NAS (QTS / QuTS hero)CVE-2018-19949

    QNAP NAS File Station Command Injection Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 9.8critical

    Added May 24, 2022

  4. Rank 14

    QNAP NAS (QTS / QuTS hero)CVE-2020-2509

    QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Apr 11, 2022

  5. Rank 15

    QNAP NAS (QTS / QuTS hero)CVE-2021-28799

    QNAP NAS Improper Authorization Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Mar 31, 2022

  6. Rank 16

    LG N1A1 NASCVE-2018-14839

    LG N1A1 NAS Remote Command Execution Vulnerability

    CVE from 2018, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  7. Rank 17

    QNAP HelpdeskCVE-2020-2506

    QNAP Helpdesk Improper Access Control Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  8. Rank 18

    Zyxel NASCVE-2020-9054

    Zyxel Multiple NAS Devices OS Command Injection Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  9. Rank 19

    D-Link NAS DNS (ShareCenter)CVE-2020-25506

    D-Link DNS-320 Device Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  10. Rank 20

    UnraidCVE-2020-5847

    Unraid Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  11. Rank 21

    QNAP Photo StationCVE-2022-27593

    QNAP Photo Station Externally Controlled Reference Vulnerability

    Ransomware

    CVSS severity 9.1critical

    Added Sep 8, 2022

  12. Rank 22

    Arcserve Unified Data Protection (UDP)CVE-2015-4068

    Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

    CVE from 2015, added in 2022

    CVSS severity 9.1critical

    Added Mar 25, 2022

  13. Rank 23

    Commvault Web ServerCVE-2025-3928

    Commvault Web Server Unspecified Vulnerability

    CVSS severity 8.8high

    Added Apr 28, 2025

  14. Rank 24

    MinIOCVE-2023-28434

    MinIO Security Feature Bypass Vulnerability

    CVSS severity 8.8high

    Added Sep 19, 2023

  15. Rank 25

    Veritas Backup ExecCVE-2021-27878

    Veritas Backup Exec Agent Command Execution Vulnerability

    RansomwareCVE from 2021, added in 2023

    CVSS severity 8.8high

    Added Apr 7, 2023

  16. Rank 26

    Veeam Backup & ReplicationCVE-2022-26500

    Veeam Backup & Replication Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 8.8high

    Added Dec 13, 2022

  17. Rank 27

    NAKIVO Backup and ReplicationCVE-2024-48248

    NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

    CVSS severity 8.6high

    Added Mar 19, 2025

  18. Rank 28

    Veritas Backup ExecCVE-2021-27876

    Veritas Backup Exec Agent File Access Vulnerability

    RansomwareCVE from 2021, added in 2023

    CVSS severity 8.1high

    Added Apr 7, 2023

  19. Rank 29

    Veeam Backup & ReplicationCVE-2023-27532

    Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

    Ransomware

    CVSS severity 7.5high

    Added Aug 22, 2023

  20. Rank 30

    MinIOCVE-2023-28432

    MinIO Information Disclosure Vulnerability

    CVSS severity 7.5high

    Added Apr 21, 2023

  21. Rank 31

    TerraMaster OSCVE-2022-24990

    TerraMaster OS Remote Command Execution Vulnerability

    Ransomware

    CVSS severity 7.5high

    Added Feb 10, 2023

  22. Rank 32

    UnraidCVE-2020-5849

    Unraid Authentication Bypass Vulnerability

    CVSS severity 7.5high

    Added Nov 3, 2021

  23. Rank 33

    Brocade Fabric OS (FOS)CVE-2025-1976

    Broadcom Brocade Fabric OS Code Injection Vulnerability

    CVSS severity 6.7medium

    Added Apr 28, 2025

  24. Rank 34

    QNAP NAS (QTS / QuTS hero)CVE-2018-19953

    QNAP NAS File Station Cross-Site Scripting Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 6.1medium

    Added May 24, 2022

  25. Rank 35

    QNAP NAS (QTS / QuTS hero)CVE-2018-19943

    QNAP NAS File Station Cross-Site Scripting Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 5.4medium

    Added May 24, 2022

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. D-Link NAS DNS (ShareCenter)CVE-2024-3272

    D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

    End of life

    CVSS severity 9.8critical

    Added Apr 11, 2024

  2. D-Link NAS DNS (ShareCenter)CVE-2024-3273

    D-Link Multiple NAS Devices Command Injection Vulnerability

    End of life

    CVSS severity 9.8critical

    Added Apr 11, 2024

  3. D-Link NAS DNS (ShareCenter)CVE-2019-16057

    D-Link DNS-320 Remote Code Execution Vulnerability

    RansomwareEnd of lifeCVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Apr 15, 2022

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.