Veeam Patches Critical RCE Vulnerabilities in Backup & Replication Software

Veeam Patches Critical RCE Vulnerabilities in Backup & Replication Software

First seen 12 Mar 2026, 17:14 UTC Digital.Nhs.UkBleepingcomputerFeedlyThehackernewsHeise.De+10 87% similarity 72.9

Article Content

Browse articles
ThreatCluster

Veeam Software has released a critical security update for its Backup & Replication platform to address multiple vulnerabilities, including three severe remote code execution (RCE) flaws. These vulnerabilities, tracked as CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708, allow authenticated users to execute arbitrary code on backup servers. The flaws affect Veeam Backup & Replication versions 12.3.2.4165 and earlier, with the patch available in version 12.3.2.4465. In total, the update resolves seven security issues, including two high-severity vulnerabilities that enable file manipulation and privilege escalation. Veeam has urged organizations to apply the update promptly, as attackers often exploit vulnerabilities shortly after patches are released. The vulnerabilities were reported through Veeam's bug bounty program and discovered during internal testing. Backup systems are increasingly targeted by attackers, particularly ransomware operators, due to their critical role in data recovery.

Key Points: • Veeam released a patch for three critical RCE vulnerabilities with CVSS scores of 9.9. • The vulnerabilities allow authenticated users to execute code on backup servers, posing a significant risk. • Organizations are urged to apply the patch immediately to protect against potential exploitation.

ThreatCluster AI

Timeline

2024-09-07
CVE-2024-40711 published
2025-03-20
CVE-2025-23120 published
2026-03-12
Veeam released security patch for Backup & Replication software
2026-03-12
CVE-2026-21666 published
2026-03-12
CVE-2026-21667 published
2026-03-12
CVE-2026-21708 published
2026-03-12
CVE-2026-21668 published
2026-03-12
CVE-2026-21672 published
2026-03-12
CVE-2026-21671 published
2026-03-12
CVE-2026-21669 published

Community

Browse all →