📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

VeraCrypt IDRIX

VeraCrypt 1.26.29

Latest tracked version 1.26.29. Release status, tracked CVEs, and automated cross-platform patching for VeraCrypt.

Category: Security

PlatformLatest versionCVEs trackedLast checked
Windows1.26.2952026-08-10

Known vulnerabilities (CVEs) in VeraCrypt

Lavawall tracks 5 published CVEs affecting VeraCrypt, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2019-195012019-12-13 13:15:12HIGH (8)VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe.LOCAL
CVE-2019-1010202019-07-23 14:15:14LOW (2)IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffer Overflow. The impact is: Minor information disclosure of kernel stack. The component is: Veracrypt NT Driver (veracrypt.sys). The attack vector is: Locally executed code, IOCTL request to driver. The fixed version is: 1.23-Hotfix-1.LOCAL
CVE-2016-12812017-01-23 21:59:01MEDIUM (4)Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and conduct DLL hijacking attacks via a Trojan horse DLL in the "application directory", as demonstrated with the USP10.dll, RichEd20.dll, NTMarta.dll and SRClient.dll DLLs.LOCAL
CVE-2015-73592017-10-03 01:29:01MEDIUM (5)The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impersonate a user at SecurityIdentify level and gain access to other users' mounted encrypted volumes.LOCAL
CVE-2015-73582017-10-03 01:29:01HIGH (7)The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.LOCAL

Why keeping VeraCrypt patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every VeraCrypt release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches VeraCrypt

Lavawall® watches VeraCrypt releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on VeraCrypt, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of VeraCrypt?
Lavawall tracks VeraCrypt at version 1.26.29 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Does VeraCrypt have known security vulnerabilities (CVEs)?
Lavawall tracks 5 CVEs for VeraCrypt and remediates them automatically as part of patching.
How do I patch VeraCrypt automatically?
Deploy the Lavawall® agent and VeraCrypt updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for VeraCrypt through public information and proprietary statistical analysis, and can patch it automatically across your fleet.