logo

Veeam Backup & Replication: CVE-2026-21666 and Related RCE Fixes

ID: 82ad06d8-9e40-5749-b5ef-2f3ff4d5b3d2

STIX ID: report--82ad06d8-9e40-5749-b5ef-2f3ff4d5b3d2

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-03-13

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Veeam released security updates for Backup & Replication (v12 build 12.3.2.4465 and v13 build 13.0.1.2067) addressing eight CVEs that include multiple authenticated RCE paths (CVSS 9.9), RCE-as-postgres for Backup Viewer, SSH credential extraction, and a Windows local privilege escalation; no active exploitation was reported, and the vendor and defenders are advised to apply the fixes and restrict administrative access to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.