Kaseya vendor intelligence

Kaseya Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Kaseya products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Kaseya KEVs Full KEV feed
Total KEVs
6
Known exploited vulnerabilities affecting Kaseya products
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Kaseya KEVs with sensor-observed exploitation activity

The catalog gap matters for Kaseya exposure

Four of the six exploited Kaseya CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss two-thirds of this vendor portfolio.

33%
Covered by CISA
67%
Beyond CISA
3
Product families

Attested Kaseya CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2021-30120

2FA bypass in Kaseya VSA <= v9.5.6

VSA High Beyond CISA 14 Aug 2026
CVE-2021-30119

Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6

VSA High Beyond CISA 14 Aug 2026
CVE-2021-30118

Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5

VSA High Beyond CISA 18 Dec 2025
CVE-2021-30116

Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6

VSA Confirmed In CISA 03 Nov 2021
CVE-2018-20753

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell...

VSA RMM Confirmed In CISA 13 Apr 2022
CVE-2015-2863

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1...

Virtual System Administrator (VSA) High Beyond CISA 20 Jul 2015

Showing 6 of 6 Kaseya known exploited vulnerabilities.

Recurring weakness patterns

Unrestricted upload, insufficiently protected credentials, and incorrect resource transfer between spheres account for three mapped occurrences across this Kaseya KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.