← Vulnerability feed

Vulnerability record · CVE-2024-40711 · published 7 September 2024

CVE-2024-40711: Veeam Backup & Replication deserialization flaw allows unauthenticated RCE

Veeam · Veeam Backup \& Replication

Veeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute arbitrary code remotely. The flaw is rated CVSS 9.8 critical and has been exploited in ransomware campaigns, making it a high-priority target for defenders.

9.8 CVSS 3.1 Critical CISA KEV since 17 Oct 2024 Known ransomware use EPSS 90% · top 0.2% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated RCE, active exploitation in ransomware campaigns, and CISA KEV listing make this an urgent risk.

What it is

Veeam Backup & Replication contains a deserialization of untrusted data vulnerability (CWE-502) that permits an unauthenticated attacker to execute arbitrary code remotely. The flaw is rated CVSS 9.8 critical and has been exploited in ransomware campaigns, making it a high-priority target for defenders.

Impact

An attacker can achieve remote code execution without authentication, potentially taking full control of the backup server and the data it manages. This can lead to data theft, ransomware deployment, and disruption of backup and recovery operations.

Attack surface

The vulnerability is reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), as indicated by the CVSS vector. Any exposed Veeam Backup & Replication service is a potential entry point.

Exploitation

CVE-2024-40711 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and public exploit code is referenced. EPSS probability is 0.90369 (99.79th percentile), indicating very high likelihood of exploitation.

What to do

  • Apply the vendor patch or mitigation instructions from Veeam KB4649 immediately.
  • If patching is not possible, discontinue use of the product or isolate it from untrusted networks per CISA guidance.
  • Restrict network access to Veeam Backup & Replication services to trusted management networks only.
  • Monitor for and block known indicators of compromise associated with ransomware groups exploiting this flaw.
  • Ensure backups are immutable and offline to prevent ransomware encryption.

Detection

  • Monitor network traffic for unexpected connections to Veeam Backup & Replication ports from untrusted sources.
  • Review Veeam logs for deserialization errors or unusual process creation events on backup servers.
  • Hunt for known exploitation artifacts or indicators published by security researchers and CISA.
  • Enable and centralize logging for Veeam services and correlate with endpoint detection alerts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-40711 to the Known Exploited Vulnerabilities catalog on 17 October 2024 as "Veeam Backup and Replication Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 November 2024.

Ransomware crews whose documented playbooks reference this CVE: