FAIL › dossier
Kaseya
VENDOR· dossier confidence 80%
Kaseya, a provider of IT management and security software, has experienced multiple critical vulnerabilities in its VSA product, leading to widespread ransomware infections and system compromises. Recent reports indicate Morgan Stanley is refinancing Kaseya debt, suggesting potential financial instability.
PROFILE
CategoryIT Management and Security SoftwareWhat they doKaseya provides IT management and security software used by managed service providers and internal IT teams. The company sells these tools under brands such as VSA, Datto, and IT Glue.
Websitehttps://notice.co/c/kaseya ↗
SECURITY POSTURE
Kaseya has a history of critical vulnerabilities leading to ransomware infections, demonstrating significant security weaknesses in their VSA product.
Notable failures
- CVE-2017-18362 (SQL injection leading to ransomware)
- CVE-2018-20753 (PowerShell RCE leading to ransomware)
- CVE-2021-30116 (Session ID exposure enabling system compromise)
Patterns: Critical RCE vulnerabilities in core product (VSA); Ransomware infection vectors
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-05-24 | CVE-2017-18362 | critical | A Kaseya VSA SQL injection vulnerability allowed unauthenticated remote access to the database, linked to ransomware attacks. |
| 2022-04-13 | CVE-2018-20753 | critical | The Kaseya VSA vulnerability allowed attackers to remotely execute PowerShell on managed devices, leading to ransomware infections across numerous organizations. |
| 2021-11-03 | CVE-2021-30116 | critical | Kaseya VSA exposed session IDs, enabling attackers to compromise systems and potentially deploy ransomware. |
| 2021-07-09 | CVE-2021-30116 | critical | CVE-2021-30116: Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild i |
| 2019-02-05 | CVE-2018-20753 | critical | CVE-2018-20753: Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0 |
SENTIMENT · TRUSTED SOURCES
synthesisnegative-0.50
Vulnerability confirmed but no major fallout reported in this source
synthesissevere-fallout-0.80
Kaseya's default configuration and unauthenticated download page directly enabled credential theft and remote code execution, leading to widespread ransomware attacks and severe reputational damage.
synthesissevere-fallout-0.80
Kaseya faced severe fallout due to the active exploitation of CVE-2018-20753 in the wild, causing widespread ransomware attacks and significant reputational damage.
Neutral technical assessment
"Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system."
NVD describes the flaw as allowing credential disclosure via an unauthenticated download page, directly enabling attackers to bypass authentication and compromise clients.
"Unauthenticated download page leaks credentials Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents dl.asp accepts credentials via a GET request Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients."
The source confirms active exploitation in January 2018, highlighting the severity of the vulnerability and Kaseya's failure to patch it before widespread abuse.
"In January 2018, attackers actively exploited this vulnerability in the wild."
DOSSIER SOURCES
- Morgan Stanley plans to raise $4 billion to refinance Kaseya debt · www.akm.ru
- Kaseya Stock | Valuation, Funding, Investors | Notice.co · notice.co
- Yamazen (TYO:8051) Company Profile & Description - Stock Analysis · stockanalysis.com
- Worldwide software supply chain attacks tracker (updated daily) · www.comparitech.com
- Is Kaseya Down Right Now? Live Status and Outage Checker · incidenthub.cloud
- Top 25 Most Significant Cyber Attacks in History · www.news4hackers.com
- Invest and Sell Kaseya Stock - Forge · forgeglobal.com
- Kaseya Stock | Valuation, Funding, Investors | Notice.co · notice.co
- Morgan Stanley plans to raise $4 billion to refinance Kaseya debt · www.akm.ru
Open questions: When were they founded? · Where is their headquarters located? · What is their ownership structure? · What is their current employee count? · What is their website address?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 06:03:40.529777+00:00