Skip to content
English

Products › IT administration and security

IT administration and security

Backup, storage and NAS

Backup software, network-attached storage (NAS) and storage arrays: prime ransomware targets.

For example: Veeam, Veritas, QNAP, Commvault.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Acronis Backup

    CVE-2026-87886

    Recently addedHunt for compromise (CISA)

    Acronis Backup Incorrect Default Permissions Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 16, 2026
    CISA deadline
    3 days
    CVSS severity
    7.8 (high)
  2. Rank 2Dell RecoverPoint

    CVE-2026-22769

    Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 18, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  3. Rank 3Commvault Command Center

    CVE-2025-34028

    Commvault Command Center Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 2, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  4. Rank 4Veeam Backup & Replication

    CVE-2024-40711

    Ransomware

    Veeam Backup and Replication Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Acronis Cyber Infrastructure (ACI)

    CVE-2023-45249

    Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 29, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 6Zyxel NAS

    CVE-2023-27992

    Zyxel Multiple NAS Devices Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Veritas Backup Exec

    CVE-2021-27877

    RansomwareCVE from 2021, added in 2023

    Veritas Backup Exec Agent Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Veeam Backup & Replication

    CVE-2022-26501

    Ransomware

    Veeam Backup & Replication Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9QNAP Photo Station

    CVE-2019-7192

    RansomwareCVE from 2019, added in 2022

    QNAP Photo Station Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  10. Rank 10QNAP NAS (QTS / QuTS hero)

    CVE-2019-7193

    RansomwareCVE from 2019, added in 2022

    QNAP QTS Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
Show 25 more vulnerabilities
  1. Rank 11QNAP Photo Station

    CVE-2019-7194

    RansomwareCVE from 2019, added in 2022

    QNAP Photo Station Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  2. Rank 12QNAP Photo Station

    CVE-2019-7195

    RansomwareCVE from 2019, added in 2022

    QNAP Photo Station Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  3. Rank 13QNAP NAS (QTS / QuTS hero)

    CVE-2018-19949

    RansomwareCVE from 2018, added in 2022

    QNAP NAS File Station Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14QNAP NAS (QTS / QuTS hero)

    CVE-2020-2509

    CVE from 2020, added in 2022

    QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15QNAP NAS (QTS / QuTS hero)

    CVE-2021-28799

    Ransomware

    QNAP NAS Improper Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16LG N1A1 NAS

    CVE-2018-14839

    CVE from 2018, added in 2022

    LG N1A1 NAS Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17QNAP Helpdesk

    CVE-2020-2506

    CVE from 2020, added in 2022

    QNAP Helpdesk Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Zyxel NAS

    CVE-2020-9054

    CVE from 2020, added in 2022

    Zyxel Multiple NAS Devices OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19D-Link NAS DNS (ShareCenter)

    CVE-2020-25506

    D-Link DNS-320 Device Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  10. Rank 20Unraid

    CVE-2020-5847

    Unraid Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  11. Rank 21QNAP Photo Station

    CVE-2022-27593

    Ransomware

    QNAP Photo Station Externally Controlled Reference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  12. Rank 22Arcserve Unified Data Protection (UDP)

    CVE-2015-4068

    CVE from 2015, added in 2022

    Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  13. Rank 23Commvault Web Server

    CVE-2025-3928

    Commvault Web Server Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 28, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  14. Rank 24MinIO

    CVE-2023-28434

    MinIO Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 19, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  15. Rank 25Veritas Backup Exec

    CVE-2021-27878

    RansomwareCVE from 2021, added in 2023

    Veritas Backup Exec Agent Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  16. Rank 26Veeam Backup & Replication

    CVE-2022-26500

    Ransomware

    Veeam Backup & Replication Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  17. Rank 27NAKIVO Backup and Replication

    CVE-2024-48248

    NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  18. Rank 28Veritas Backup Exec

    CVE-2021-27876

    RansomwareCVE from 2021, added in 2023

    Veritas Backup Exec Agent File Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  19. Rank 29Veeam Backup & Replication

    CVE-2023-27532

    Ransomware

    Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 22, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  20. Rank 30MinIO

    CVE-2023-28432

    MinIO Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 21, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  21. Rank 31TerraMaster OS

    CVE-2022-24990

    Ransomware

    TerraMaster OS Remote Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  22. Rank 32Unraid

    CVE-2020-5849

    Unraid Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  23. Rank 33Brocade Fabric OS (FOS)

    CVE-2025-1976

    Broadcom Brocade Fabric OS Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 28, 2025
    CISA deadline
    21 days
    CVSS severity
    6.7 (medium)
  24. Rank 34QNAP NAS (QTS / QuTS hero)

    CVE-2018-19953

    RansomwareCVE from 2018, added in 2022

    QNAP NAS File Station Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  25. Rank 35QNAP NAS (QTS / QuTS hero)

    CVE-2018-19943

    RansomwareCVE from 2018, added in 2022

    QNAP NAS File Station Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. D-Link NAS DNS (ShareCenter)

    CVE-2024-3272

    End of life

    D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. D-Link NAS DNS (ShareCenter)

    CVE-2024-3273

    End of life

    D-Link Multiple NAS Devices Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. D-Link NAS DNS (ShareCenter)

    CVE-2019-16057

    RansomwareEnd of lifeCVE from 2019, added in 2022

    D-Link DNS-320 Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.