Veeam Backup & Replication: CVE-2026-21666 and Related RCE Fixes
ID: 82ad06d8-9e40-5749-b5ef-2f3ff4d5b3d2
STIX ID: report--82ad06d8-9e40-5749-b5ef-2f3ff4d5b3d2
Feed Name: SOCRadar Blog
Threat Score
Veeam released security updates for Backup & Replication (v12 build 12.3.2.4465 and v13 build 13.0.1.2067) addressing eight CVEs that include multiple authenticated RCE paths (CVSS 9.9), RCE-as-postgres for Backup Viewer, SSH credential extraction, and a Windows local privilege escalation; no active exploitation was reported, and the vendor and defenders are advised to apply the fixes and restrict administrative access to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
