Products › IT administration and security
IT administration and security
Backup, storage and NAS
Backup software, network-attached storage (NAS) and storage arrays: prime ransomware targets.
For example: Veeam, Veritas, QNAP, Commvault.
-
2 vulnerabilities added in the last 12 months
-
38 exploited vulnerabilities in the catalog, in total
-
1 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Acronis 2 vulnerabilities · 1 in the last 12 months
- Arcserve 1 vulnerability
- Brocade 1 vulnerability
- Commvault 2 vulnerabilities
- D-Link 4 vulnerabilities
- Dell 1 vulnerability · 1 in the last 12 months
- LG 1 vulnerability
- MinIO 2 vulnerabilities
- NAKIVO 1 vulnerability
- QNAP 11 vulnerabilities
- TerraMaster 1 vulnerability
- Unraid 2 vulnerabilities
- Veeam 4 vulnerabilities
- Veritas 3 vulnerabilities
- Zyxel 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Virtualization, VDI and cloud 35 vulnerabilities
- Managed file transfer (MFT) 33 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Acronis Backup
CVE-2026-87886Recently addedHunt for compromise (CISA)
Acronis Backup Incorrect Default Permissions Vulnerability
Added to the catalog less than 30 days ago: ranked by date added.
- Added
- Sep 16, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.8 (high)
Rank 2Dell RecoverPoint
CVE-2026-22769Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 18, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 3Commvault Command Center
CVE-2025-34028Commvault Command Center Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 2, 2025
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 4Veeam Backup & Replication
CVE-2024-40711Ransomware
Veeam Backup and Replication Deserialization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 5Acronis Cyber Infrastructure (ACI)
CVE-2023-45249Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 29, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 6Zyxel NAS
CVE-2023-27992Zyxel Multiple NAS Devices Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 23, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7Veritas Backup Exec
CVE-2021-27877RansomwareCVE from 2021, added in 2023
Veritas Backup Exec Agent Improper Authentication Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8Veeam Backup & Replication
CVE-2022-26501Ransomware
Veeam Backup & Replication Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9QNAP Photo Station
CVE-2019-7192RansomwareCVE from 2019, added in 2022
QNAP Photo Station Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 10QNAP NAS (QTS / QuTS hero)
CVE-2019-7193RansomwareCVE from 2019, added in 2022
QNAP QTS Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Show 25 more vulnerabilities
Rank 11QNAP Photo Station
CVE-2019-7194RansomwareCVE from 2019, added in 2022
QNAP Photo Station Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 12QNAP Photo Station
CVE-2019-7195RansomwareCVE from 2019, added in 2022
QNAP Photo Station Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 8, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 13QNAP NAS (QTS / QuTS hero)
CVE-2018-19949RansomwareCVE from 2018, added in 2022
QNAP NAS File Station Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14QNAP NAS (QTS / QuTS hero)
CVE-2020-2509CVE from 2020, added in 2022
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 11, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15QNAP NAS (QTS / QuTS hero)
CVE-2021-28799Ransomware
QNAP NAS Improper Authorization Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 31, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 16LG N1A1 NAS
CVE-2018-14839CVE from 2018, added in 2022
LG N1A1 NAS Remote Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 17QNAP Helpdesk
CVE-2020-2506CVE from 2020, added in 2022
QNAP Helpdesk Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 18Zyxel NAS
CVE-2020-9054CVE from 2020, added in 2022
Zyxel Multiple NAS Devices OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19D-Link NAS DNS (ShareCenter)
CVE-2020-25506D-Link DNS-320 Device Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 20Unraid
CVE-2020-5847Unraid Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 21QNAP Photo Station
CVE-2022-27593Ransomware
QNAP Photo Station Externally Controlled Reference Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 22Arcserve Unified Data Protection (UDP)
CVE-2015-4068CVE from 2015, added in 2022
Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 23Commvault Web Server
CVE-2025-3928Commvault Web Server Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 28, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 24MinIO
CVE-2023-28434MinIO Security Feature Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 19, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 25Veritas Backup Exec
CVE-2021-27878RansomwareCVE from 2021, added in 2023
Veritas Backup Exec Agent Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 26Veeam Backup & Replication
CVE-2022-26500Ransomware
Veeam Backup & Replication Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 13, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 27NAKIVO Backup and Replication
CVE-2024-48248NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.6 (high)
Rank 28Veritas Backup Exec
CVE-2021-27876RansomwareCVE from 2021, added in 2023
Veritas Backup Exec Agent File Access Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 29Veeam Backup & Replication
CVE-2023-27532Ransomware
Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 30MinIO
CVE-2023-28432MinIO Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 21, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 31TerraMaster OS
CVE-2022-24990Ransomware
TerraMaster OS Remote Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 32Unraid
CVE-2020-5849Unraid Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.5 (high)
Rank 33Brocade Fabric OS (FOS)
CVE-2025-1976Broadcom Brocade Fabric OS Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 28, 2025
- CISA deadline
- 21 days
- CVSS severity
- 6.7 (medium)
Rank 34QNAP NAS (QTS / QuTS hero)
CVE-2018-19953RansomwareCVE from 2018, added in 2022
QNAP NAS File Station Cross-Site Scripting Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 6.1 (medium)
Rank 35QNAP NAS (QTS / QuTS hero)
CVE-2018-19943RansomwareCVE from 2018, added in 2022
QNAP NAS File Station Cross-Site Scripting Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 24, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.4 (medium)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
D-Link NAS DNS (ShareCenter)
CVE-2024-3272End of life
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 11, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link NAS DNS (ShareCenter)
CVE-2024-3273End of life
D-Link Multiple NAS Devices Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 11, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link NAS DNS (ShareCenter)
CVE-2019-16057RansomwareEnd of lifeCVE from 2019, added in 2022
D-Link DNS-320 Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.