CVE-2026-21666
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2026-21666 is an improper access control vulnerability in Veeam Backup & Replication that allows an authenticated domain user to perform remote code execution (RCE) on the Backup Server. It affects versions from 12.0.0.1402 up to (but not including) 12.3.2.4465. The vulnerability was published on March 12, 2026, with a patch released via Veeam KB4830. It carries a CVSS v3.1 base score of 8.8 (High) per NVD, though ENISA rates it at 10.0 (Critical) using a scope-changed vector (Veeam KB4830, Feedly).

Technical details

The root cause is classified as CWE-284 (Improper Access Control), meaning the application fails to adequately restrict what an authenticated domain user can do on the Backup Server. An attacker with low-privilege domain credentials can send crafted network requests to the Backup Server over the network without requiring any user interaction, bypassing authorization controls to achieve code execution. No specific technical write-up or public PoC code has been disclosed as of the time of reporting (Veeam KB4830, Feedly).

Impact

Successful exploitation grants an authenticated attacker full remote code execution on the Veeam Backup Server, resulting in complete compromise of the backup infrastructure. This includes unauthorized access to sensitive backup data, modification or deletion of recovery points, and potential lateral movement within the broader enterprise environment. The high confidentiality, integrity, and availability impacts make this particularly dangerous in environments where Veeam manages critical business data and disaster recovery capabilities (Feedly, BleepingComputer).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.003 (0.3%), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam products have historically been targeted by ransomware groups, and community discussion (including Reddit threads referencing CVSS scores as high as 9.9) suggests elevated attention from the security community (Reddit, BulwarkBlack).

Mitigation and workarounds

Veeam has released a patch addressing this vulnerability in version 12.3.2.4465 and later, documented in KB4830. Organizations running Veeam Backup & Replication versions 12.0.0.1402 through 12.3.2.4464 should upgrade immediately. As interim mitigations, implement network segmentation to restrict access to Backup Servers from untrusted networks, enforce strong access controls on domain accounts, and consider multi-factor authentication for administrative access to backup infrastructure (Veeam KB4830, Feedly).

Community reactions

Veeam issued KB4830 addressing seven critical vulnerabilities including CVE-2026-21666, prompting broad coverage from outlets including BleepingComputer, The Hacker News, CSO Online, and TechRadar, all urging immediate patching (BleepingComputer, The Hacker News, CSO Online). The NCSC Ireland published an advisory, and security firms including SOCRadar, SecPod, and Greenbone highlighted the risk to backup infrastructure (NCSC Ireland, SOCRadar). Community discussion on Reddit and social media noted the severity, with some sources citing CVSS scores as high as 9.9, and security researchers flagged the historical pattern of ransomware groups targeting Veeam vulnerabilities (Reddit, BulwarkBlack).

Additional resources


SourceThis report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21708CRITICAL9.9
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMar 12, 2026
CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management