CVE-2026-21669: 
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2026-21669 is a code injection vulnerability in Veeam Backup & Replication that allows an authenticated domain user to perform remote code execution (RCE) on the Backup Server. It affects versions 13.0.0.496 through 13.0.1.1071, with the fix available in version 13.0.1.2067. The vulnerability was published on March 12, 2026, and a patch was released by Veeam shortly thereafter. It carries a CVSS v3.1 base score of 9.9 (Critical) (Veeam KB4831).

Technical details

The root cause is classified under CWE-94 (Improper Control of Generation of Code / Code Injection) and CWE-693 (Protection Mechanism Failure), indicating that user-supplied input is improperly handled in a way that allows code to be generated and executed server-side (Veeam KB4831). The attack vector is network-based, requires low privileges (an authenticated domain user account), no user interaction, and has a changed scope — meaning a successful exploit can impact resources beyond the vulnerable component itself. No public proof-of-concept exploit has been confirmed, but the vulnerability has been weaponized by threat actors in the wild (CyberSecBrief).

Impact

Successful exploitation grants an authenticated domain user the ability to execute arbitrary code remotely on the Backup Server, resulting in full compromise of confidentiality, integrity, and availability of the backup infrastructure. Attackers can exfiltrate sensitive backup data, manipulate or destroy backup jobs, and disrupt availability of critical recovery systems. Given that backup servers often hold credentials and data for the broader enterprise environment, exploitation can facilitate lateral movement and ransomware deployment (Veeam KB4831, Arctic Wolf).

Exploitability

No public proof-of-concept exploit has been confirmed as of the time of reporting. However, the Akira ransomware group and threat actor Storm-1567 have been identified as actively exploiting this vulnerability in the wild (CyberSecBrief). The EPSS score is approximately 0.0023 (0.23%), reflecting a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is detectable by Qualys (detection ID 386795) and Tenable Nessus (plugin 303202) (Veeam KB4831). CISA KEV catalog status is not confirmed in available sources.

Exploitation steps

  1. Reconnaissance: Identify Veeam Backup & Replication servers running versions 13.0.0.496 through 13.0.1.1071 using network scanning tools (e.g., Shodan, Nmap) or internal asset inventory.
  2. Obtain domain credentials: Acquire any valid domain user account — through phishing, credential stuffing, or prior compromise — as only low-privilege authentication is required.
  3. Authenticate to the Backup Server: Use the domain credentials to authenticate to the Veeam Backup & Replication service over the network.
  4. Inject malicious code: Submit a crafted request exploiting the improper code generation controls (CWE-94) to inject and execute arbitrary code on the Backup Server.
  5. Achieve RCE: The injected code executes in the context of the Backup Server process, enabling the attacker to deploy ransomware payloads (e.g., Akira), exfiltrate backup data, or establish persistence for further lateral movement (Veeam KB4831, CyberSecBrief).

Indicators of compromise

  • Network: Unexpected outbound connections from the Veeam Backup Server to external or unusual internal IP addresses; anomalous authenticated API or service calls from non-administrative domain accounts.
  • Logs: Veeam service logs showing code execution or unusual job activity initiated by low-privilege domain accounts; authentication events from unexpected source hosts in Windows Security Event Logs (Event ID 4624/4625).
  • File System: New or modified executables, scripts, or DLLs in Veeam installation directories; presence of ransomware artifacts (e.g., Akira-associated file extensions or ransom notes) on the backup server.
  • Process: Unusual child processes spawned by Veeam service processes (e.g., cmd.exe, powershell.exe, wscript.exe); unexpected scheduled tasks or services created under the Veeam service account (Arctic Wolf, CyberSecBrief).

Mitigation and workarounds

Veeam has released a patch in version 13.0.1.2067, which resolves CVE-2026-21669 and related critical flaws. Organizations should upgrade all Veeam Backup & Replication installations from affected versions (13.0.0.496–13.0.1.1071) to 13.0.1.2067 or later immediately (Veeam KB4831). As interim mitigations, implement network segmentation to restrict Backup Server access to trusted administrative systems only, enforce the principle of least privilege for domain accounts with access to backup infrastructure, and monitor backup server access logs for suspicious authenticated activity (Arctic Wolf).

Community reactions

Veeam published a security advisory (KB4831) and the community responded quickly, with coverage from BleepingComputer, The Hacker News, SecurityOnline, and Heise noting the severity of the seven critical flaws patched in the same release (BleepingComputer, The Hacker News). Arctic Wolf published a detailed blog post highlighting the authenticated nature of the vulnerabilities and the risk to backup infrastructure (Arctic Wolf). Security researchers and threat intelligence teams flagged the involvement of the Akira ransomware group and Storm-1567, elevating urgency for patching (CyberSecBrief). The NCSC Ireland also issued an advisory referencing the related CVE cluster (NCSC Ireland).

Additional resources


Source: This report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-58070MEDIUM6.8
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesAug 26, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management