
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21666 is an improper access control vulnerability in Veeam Backup & Replication that allows an authenticated domain user to perform remote code execution (RCE) on the Backup Server. It affects versions from 12.0.0.1402 up to (but not including) 12.3.2.4465. The vulnerability was published on March 12, 2026, with a patch released via Veeam KB4830. It carries a CVSS v3.1 base score of 8.8 (High) per NVD, though ENISA rates it at 10.0 (Critical) using a scope-changed vector (Veeam KB4830, Feedly).
The root cause is classified as CWE-284 (Improper Access Control), meaning the application fails to adequately restrict what an authenticated domain user can do on the Backup Server. An attacker with low-privilege domain credentials can send crafted network requests to the Backup Server over the network without requiring any user interaction, bypassing authorization controls to achieve code execution. No specific technical write-up or public PoC code has been disclosed as of the time of reporting (Veeam KB4830, Feedly).
Successful exploitation grants an authenticated attacker full remote code execution on the Veeam Backup Server, resulting in complete compromise of the backup infrastructure. This includes unauthorized access to sensitive backup data, modification or deletion of recovery points, and potential lateral movement within the broader enterprise environment. The high confidentiality, integrity, and availability impacts make this particularly dangerous in environments where Veeam manages critical business data and disaster recovery capabilities (Feedly, BleepingComputer).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.003 (0.3%), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam products have historically been targeted by ransomware groups, and community discussion (including Reddit threads referencing CVSS scores as high as 9.9) suggests elevated attention from the security community (Reddit, BulwarkBlack).
Veeam has released a patch addressing this vulnerability in version 12.3.2.4465 and later, documented in KB4830. Organizations running Veeam Backup & Replication versions 12.0.0.1402 through 12.3.2.4464 should upgrade immediately. As interim mitigations, implement network segmentation to restrict access to Backup Servers from untrusted networks, enforce strong access controls on domain accounts, and consider multi-factor authentication for administrative access to backup infrastructure (Veeam KB4830, Feedly).
Veeam issued KB4830 addressing seven critical vulnerabilities including CVE-2026-21666, prompting broad coverage from outlets including BleepingComputer, The Hacker News, CSO Online, and TechRadar, all urging immediate patching (BleepingComputer, The Hacker News, CSO Online). The NCSC Ireland published an advisory, and security firms including SOCRadar, SecPod, and Greenbone highlighted the risk to backup infrastructure (NCSC Ireland, SOCRadar). Community discussion on Reddit and social media noted the severity, with some sources citing CVSS scores as high as 9.9, and security researchers flagged the historical pattern of ransomware groups targeting Veeam vulnerabilities (Reddit, BulwarkBlack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."