
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21671 is a code injection vulnerability in Veeam Backup & Replication that allows an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments. It affects Veeam Backup & Replication versions up to and including 13.0.1.1071. The vulnerability was published on March 12, 2026, with a patch reference added shortly after. It carries a CVSS v3.1 base score of 9.1 (Critical) (Veeam KB4831, Feedly).
The vulnerability is classified under CWE-94 (Improper Control of Generation of Code / Code Injection) and CWE-693 (Protection Mechanism Failure), indicating that user-controlled input is improperly handled in a way that allows arbitrary code to be injected and executed server-side (Feedly). The attack vector is network-based with low attack complexity, requiring high privileges (Backup Administrator role) and no user interaction. The scope is changed, meaning successful exploitation can impact components beyond the vulnerable application itself. Exploitation is specific to HA (high availability) deployment configurations of Veeam Backup & Replication (Veeam KB4831).
Successful exploitation grants an authenticated Backup Administrator the ability to execute arbitrary code remotely on HA-configured Veeam Backup & Replication servers, resulting in high impact to confidentiality, integrity, and availability. An attacker could access, modify, or delete backup data — including sensitive backup copies of production systems — and potentially pivot to other systems within the environment. Given that backup infrastructure often holds credentials and data for a wide range of enterprise systems, compromise could facilitate broader lateral movement and ransomware deployment (Feedly, Arctic Wolf).
As of the time of reporting, there is no public proof-of-concept (PoC) exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.0027 (0.27%), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, security researchers and media have noted that Veeam vulnerabilities historically attract ransomware group attention (Bulwark Black, The Hacker News).
cmd.exe, powershell.exe, bash) not associated with normal backup operations.Veeam has released a patch addressing CVE-2026-21671; administrators should update Veeam Backup & Replication to a version beyond 13.0.1.1071 as detailed in the official knowledge base article (Veeam KB4831). As interim mitigations, organizations should strictly limit assignment of the Backup Administrator role to only necessary personnel, implement network segmentation to restrict access to HA deployment nodes, and enforce strong credential management and multi-factor authentication for privileged accounts. Continuous monitoring of Backup Administrator account activity and review of access logs for anomalous behavior is also recommended (Feedly, SecPod).
The vulnerability was covered by multiple security news outlets including The Hacker News, Security Online, The Cyber Express, and Heise, all highlighting the broader batch of seven critical Veeam flaws patched simultaneously (The Hacker News, Security Online). Arctic Wolf published a detailed advisory noting the authenticated nature of the vulnerabilities and urging immediate patching (Arctic Wolf). Bulwark Black specifically flagged that critical Veeam vulnerabilities have historically attracted ransomware group attention, urging organizations to treat this patch cycle with urgency (Bulwark Black). Social media discussion was noted on Mastodon and Bluesky, primarily from security news aggregators.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."