CVE-2026-21667
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2026-21667 is an improper access control vulnerability in Veeam Backup & Replication that allows an authenticated domain user to perform remote code execution (RCE) on the Backup Server. It affects versions 12.0.0.1402 through 12.3.2.4465 (exclusive) and was published on March 12, 2026. The vulnerability was assigned a CVSS v3.1 base score of 8.8 (High) by NVD, though ENISA's EU Vulnerability Database scores it at 10.0 (Critical) using a broader scope vector. A patch was made available on March 30, 2026 (Veeam KB4830).

Technical details

The root cause is classified as CWE-284 (Improper Access Control), where the Backup Server fails to adequately restrict operations available to authenticated domain users. An attacker with low-privilege domain credentials can send crafted network requests to the Backup Server over the network (attack vector: Network, complexity: Low) without requiring any user interaction, triggering arbitrary code execution. No public technical write-up or proof-of-concept code detailing the specific vulnerable endpoint or payload has been identified at this time (Veeam KB4830, Feedly).

Impact

Successful exploitation grants an attacker full remote code execution on the Backup Server, resulting in high confidentiality, integrity, and availability impact. This can lead to complete compromise of the backup infrastructure — including unauthorized access to sensitive backup data, modification or deletion of backup jobs and data, and disruption of backup and recovery operations. Because backup servers typically hold credentials and data for a broad set of systems, a compromised Backup Server poses significant lateral movement risk across the enterprise (Veeam KB4830, BleepingComputer).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.30%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Veeam Backup & Replication has historically been a high-value target for ransomware groups, and the low privilege requirement makes this vulnerability attractive for threat actors (BleepingComputer, Bulwark Black).

Mitigation and workarounds

Veeam has released version 12.3.2.4465 as the patched release; all users running versions 12.0.0.1402 through earlier 12.3.x builds should upgrade immediately (Veeam KB4830). As interim mitigations, restrict network access to the Backup Server to authorized administrators only, implement network segmentation to limit the blast radius of a potential compromise, and monitor Backup Server logs for suspicious activity originating from authenticated domain accounts. Enforce strong access control policies for all domain accounts with access to backup infrastructure.

Community reactions

The disclosure generated significant coverage across security media, with BleepingComputer, The Hacker News, CSO Online, and TechRadar all reporting on the broader batch of seven critical Veeam vulnerabilities patched simultaneously (BleepingComputer, The Hacker News). Security researchers and community members on Reddit and Mastodon highlighted the risk given Veeam's historical targeting by ransomware operators (Reddit). Ireland's NCSC issued an advisory referencing the related CVE-2026-21666 vulnerability in the same patch batch, underscoring the urgency of patching (NCSC Ireland). Bulwark Black specifically noted that ransomware groups were paying attention to this cluster of Veeam flaws (Bulwark Black).

Additional resources


SourceThis report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21708CRITICAL9.9
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:backup_and_replication
NoYesMar 12, 2026
CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management