Bleepingcomputer
Veeam Patches Critical RCE Vulnerabilities in Backup & Replication Software
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Veeam Software has released a critical security update for its Backup & Replication platform to address multiple vulnerabilities, including three severe remote code execution (RCE) flaws. These vulnerabilities, tracked as CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708, allow authenticated users to execute arbitrary code on backup servers. The flaws affect Veeam Backup & Replication versions 12.3.2.4165 and earlier, with the patch available in version 12.3.2.4465. In total, the update resolves seven security issues, including two high-severity vulnerabilities that enable file manipulation and privilege escalation. Veeam has urged organizations to apply the update promptly, as attackers often exploit vulnerabilities shortly after patches are released. The vulnerabilities were reported through Veeam's bug bounty program and discovered during internal testing. Backup systems are increasingly targeted by attackers, particularly ransomware operators, due to their critical role in data recovery.
Key Points: • Veeam released a patch for three critical RCE vulnerabilities with CVSS scores of 9.9. • The vulnerabilities allow authenticated users to execute code on backup servers, posing a significant risk. • Organizations are urged to apply the patch immediately to protect against potential exploitation.