
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21669 is a code injection vulnerability in Veeam Backup & Replication that allows an authenticated domain user to perform remote code execution (RCE) on the Backup Server. It affects versions 13.0.0.496 through 13.0.1.1071, with the fix available in version 13.0.1.2067. The vulnerability was published on March 12, 2026, and a patch was released by Veeam shortly thereafter. It carries a CVSS v3.1 base score of 9.9 (Critical) (Veeam KB4831).
The root cause is classified under CWE-94 (Improper Control of Generation of Code / Code Injection) and CWE-693 (Protection Mechanism Failure), indicating that user-supplied input is improperly handled in a way that allows code to be generated and executed server-side (Veeam KB4831). The attack vector is network-based, requires low privileges (an authenticated domain user account), no user interaction, and has a changed scope — meaning a successful exploit can impact resources beyond the vulnerable component itself. No public proof-of-concept exploit has been confirmed, but the vulnerability has been weaponized by threat actors in the wild (CyberSecBrief).
Successful exploitation grants an authenticated domain user the ability to execute arbitrary code remotely on the Backup Server, resulting in full compromise of confidentiality, integrity, and availability of the backup infrastructure. Attackers can exfiltrate sensitive backup data, manipulate or destroy backup jobs, and disrupt availability of critical recovery systems. Given that backup servers often hold credentials and data for the broader enterprise environment, exploitation can facilitate lateral movement and ransomware deployment (Veeam KB4831, Arctic Wolf).
No public proof-of-concept exploit has been confirmed as of the time of reporting. However, the Akira ransomware group and threat actor Storm-1567 have been identified as actively exploiting this vulnerability in the wild (CyberSecBrief). The EPSS score is approximately 0.0023 (0.23%), reflecting a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is detectable by Qualys (detection ID 386795) and Tenable Nessus (plugin 303202) (Veeam KB4831). CISA KEV catalog status is not confirmed in available sources.
cmd.exe, powershell.exe, wscript.exe); unexpected scheduled tasks or services created under the Veeam service account (Arctic Wolf, CyberSecBrief).Veeam has released a patch in version 13.0.1.2067, which resolves CVE-2026-21669 and related critical flaws. Organizations should upgrade all Veeam Backup & Replication installations from affected versions (13.0.0.496–13.0.1.1071) to 13.0.1.2067 or later immediately (Veeam KB4831). As interim mitigations, implement network segmentation to restrict Backup Server access to trusted administrative systems only, enforce the principle of least privilege for domain accounts with access to backup infrastructure, and monitor backup server access logs for suspicious authenticated activity (Arctic Wolf).
Veeam published a security advisory (KB4831) and the community responded quickly, with coverage from BleepingComputer, The Hacker News, SecurityOnline, and Heise noting the severity of the seven critical flaws patched in the same release (BleepingComputer, The Hacker News). Arctic Wolf published a detailed blog post highlighting the authenticated nature of the vulnerabilities and the risk to backup infrastructure (Arctic Wolf). Security researchers and threat intelligence teams flagged the involvement of the Akira ransomware group and Storm-1567, elevating urgency for patching (CyberSecBrief). The NCSC Ireland also issued an advisory referencing the related CVE cluster (NCSC Ireland).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."