CVE-2021-27877PoC(veritas / backup_exec)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

1.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-04-28. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backup_exec

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
backup_exec

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-02: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-05: 107-0207-05
Signal classification2 categories
PoC
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-07-021
PoC1
2026-07-051
General1
Full discourse2 posts
  • Yash Swarup@wazirsec
    PoC

    Hi everyone, Blogged about a deep dive into CVE-2021-27877, debugging a public exploit and validating remote code execution. #CyberSecurity #PenetrationTesting #bugbounty #bugbountytips #hacking https://yashswarup12.medium.com/cve-2021-27877-analyzing-and-exploiting-veritas-backup-exec-remote-code-execution-5e31bc41eeef

    Post summary

    The tweet promotes a Medium article that deep‑dives into CVE‑2021‑27877, debugs a public exploit and confirms remote code execution. It does not report active attacks, patches, or a new exploit tool.

    00021155
    114 followersView on X
  • BBWriteup@bbwriteup
    General

    "CVE-2021-27877: Analyzing and Exploiting Veritas Backup Exec Remote Code Execution" by Yash Swarup #InfoSec #CyberSecurity #Hacking #BugBounty https://yashswarup12.medium.com/cve-2021-27877-analyzing-and-exploiting-veritas-backup-exec-remote-code-execution-5e31bc41eeef

    Post summary

    The article appears to provide an analysis of CVE‑2021‑27877, describing its Remote Code Execution vulnerability, but no PoC, exploit code, active exploitation evidence, or patch information is disclosed in the excerpt.

    00010102
    760 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appveritasbackup_exec---

Explore more