CVE-2026-21666Patch(veeam / veeam_backup_\&_replication)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch veeam veeam_backup_\&_replication systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

0.8/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • veeam_backup_\&_replication

Threat summary

  • Patch or workaround signal is available
  • 26 mentions across 8 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 22 signals
  • Disclosure: 9 classified signals
  • False Positive: 1 classified signal
  • Peaked 6d ago at 15 mentions (2026-03-13); latest day: 2
  • 26 total mentions across 8 days

Affected systems

Vendors
Products
veeam_backup_\&_replication

Deep dive

Activity timeline26 mentions / 8d
0481115Mentions · 2026-03-12: 3Mentions · 2026-03-13: 15Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 2Mentions · 2026-03-17: 1Mentions · 2026-04-03: 1Mentions · 2026-09-17: 2Patch / Workaround · 2026-03-13: 11Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 13Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-04-03: 1Technical Details · 2026-09-17: 103-1203-1303-1403-1503-1603-1704-0309-17
Signal classification4 categories
Patch
1557.7%
Disclosure
934.6%
False Positive
13.8%
General
13.8%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure3
2026-03-1315
Disclosure5Patch10
2026-03-141
Patch1
2026-03-151
Patch1
2026-03-162
Patch2
2026-03-171
Patch1
2026-04-031
Disclosure1
2026-09-172
False Positive1General1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    Veeam urgently patches critical 9.9 CVSS RCE flaws (CVE-2026-21666, CVE-2026-21708) in Backup & Replication 12.3.2. Update your servers immediately. #Veeam #CVE #CyberSecurity #InfoSec #RCE #BackupSecurity #PatchAlert #Vulnerability #TechNews https://securityonline.info/total-takeover-veeam-patches-critical-9-9-cvss-rce-flaws-in-backup-replication-12-3-2/

    Post summary

    Veeam has issued urgent patches for two critical RCE vulnerabilities (CVE-2026-21666 and CVE-2026-21708) with a CVSS score of 9.9, urging users to update their Backup & Replication 12.3.2 servers immediately.

    130102873
    10.6K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na sérii RCE zranitelností ve Veeam Backup and Replication, CVE-2026-21666, CVE-2026-21667, CVE-2026-21668 a další. V produktu Veeam Backup & Replication byla identifikována série kritických a vysoce závažných zranitelností. Úspěšné zneužití těchto zranitelností by mohlo umožnit ověřeným uživatelům nebo útočníkům s nízkými oprávněními spustit libovolný kód, eskalovat oprávnění, obejít bezpečnostní omezení, manipulovat se soubory úložiště nebo extrahovat uložené přihlašovací údaje. Zranitelnosti postihují všechny produkty Veeam Backup and Replication do verze 12.3.2.4165 a 13.0.1.1071. 📌Doporučujeme aktualizovat na verzi 12.3.2.4465 nebo 13.0.1.2067.

    Post summary

    The text alerts users to a series of critical RCE vulnerabilities in Veeam Backup & Replication and advises updating to specific newer releases to remediate the issue.

    03050978
    4.2K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Veeam warns of critical flaws exposing backup servers to RCE attacks https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/ 『(直訳) RCE セキュリティ脆弱性 ( CVE-2026-21666、CVE-2026-21667、CVE-2026-21669として追跡) により、低い権限を持つドメイン ユーザーが、複雑度の低い攻撃で脆弱なバックアップ サーバー上でリモート コードを実行できるようになります。4 番目の脆弱性 ( CVE-2026-21708として追跡) により、バックアップ ビューアーが postgres ユーザーとしてリモート コード実行を取得できるようになります。』

    Post summary

    The article announces four critical RCE vulnerabilities in Veeam backup servers, detailing CVE identifiers and the nature of the attacks, but it does not provide PoC, exploits, or patch information.

    100311.2K
    11.4K followersView on X
  • SOCRadar®@socradar
    Patch

    Veeam patched 8 vulnerabilities in Backup & Replication, including CVSS 9.9 RCE flaws like CVE-2026-21666. Authenticated users can achieve RCE, risking ransomware exposure. Upgrade immediately. Read more at the link below. https://hubs.la/Q046Hdmv0

    Post summary

    The notice highlights that Veeam has patched eight high‑severity RCE vulnerabilities, including CVE‑2026‑21666, and urges users to apply the fix immediately.

    10030423
    5.6K followersView on X
  • CVE Brief@DailyCVEBrief
    False Positive

    LOOK BACK: A CVSS 9.9 RCE on Veeam backup servers, in a product with four ransomware-linked entries in CISA KEV. Six months on, CVE-2026-21666 has no KEV listing, no PoC and no exploitation. The best-documented thing about it turned out to be its paperwork. https://t.co/iEdC6fzoxc

    Post summary

    The tweet acknowledges CVE-2026-21666 as a CVSS 9.9 RCE in Veeam but debunks its real-world significance, noting no KEV listing, no PoC, and no exploitation after six months, characterizing it as mere paperwork.

    1001095
    32 followersView on X
  • Israel@f1tym1
    Patch

    Veeam Backup & Replication: CVE-2026-21666 and Related RCE Fixes https://ift.tt/Wx9TDVR Veeam Backup & Replication: CVE-2026-21666 and Related RCE Fixes Veeam shipped new security fixes for Veeam Backup & Replication (VBR) on March 12, 2026, publishing separate KBs for its s…

    Post summary

    The article announces that Veeam released security patches for CVE‑2026‑21666, a remote code execution vulnerability, and provides the related update information in new knowledge‑base articles.

    0101047
    962 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Veeam released update 12.3.2.4465 fixing seven security flaws in Backup & Replication, including critical RCE bugs CVE-2026-21666 and CVE-2026-21667 with a 9.9 severity score. #BackupSecurity #RCEVulnerabilities #USA https://ift.tt/HRU3XWP

    Post summary

    Veeam released an update that patches seven security flaws, including two critical RCE vulnerabilities (CVE-2026-21666 and CVE-2026-21667) with a 9.9 severity score.

    00010171
    3.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-21666 PT-Identifier: PT-2026-24952 Vendor: Veeam Product: Backup and Replication CVSS: 10.0 Credits: n/a Description: A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21666 • https://www.veeam.com/kb4830 #dbugs_vuln

    Post summary

    A high‑severity RCE vulnerability (CVE‑2026‑21666) in Veeam Backup and Replication is disclosed with technical details but no evidence of active exploitation, PoC, or patch information is provided.

    0001073
    593 followersView on X
  • Cyber Cachce | بالعربي@Cybercachear
    Disclosure

    📌 أصدرت Veeam تحديثات أمان لمعالجة سبع ثغرات حرجة في Backup & Replication قد تسمح بتنفيذ تعليمات برمجية عن بُعد. أبرزها CVE-2026-21666 بتقييم CVSS 9.9، التي تتيح لمستخدم نطاق مصادق تنفيذ RCE على خادم النسخ الاحتياطي. بقية الثغرات غير مذكورة بالكامل في النص. #الامن_السيبراني https://t.co/RG8oMvQBCY

    Post summary

    Veeam announced security updates for seven critical Backup & Replication vulnerabilities, notably CVE-2026-21666 with CVSS 9.9 that allows RCE, but no PoC, exploit tool, or active exploitation details are provided.

    0001079
    433 followersView on X
  • Orizon@OrizonCyber
    Disclosure

    Veeam dropping 7 critical RCE vulns in their backup software 💀 CVE-2026-21666 scored 9.9/10 on CVSS Your "secure" backups just became the entry point How many orgs are running unpatched Veeam right now? #infosec #CVE https://t.co/qMqrdEeksb

    Post summary

    The post announces seven high‑severity RCE vulnerabilities in Veeam backup software, highlighting the CVSS score and urging attention but providing no exploit code, patch information, or evidence of active exploitation.

    1000039
    5 followersView on X
  • Machina Record@MachinaRecord
    Patch

    🩹シスコ、IOS XRソフトウェアにおける深刻度Highの脆弱性4件にパッチ(CVE-2026-20040、CVE-2026-20046他) ⚠️Veeam、VBRにおけるCriticalなRCE脆弱性などについて警告(CVE-2026-21666、CVE-2026-21667他) 〜サイバーアラート3月13日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44562/

    Post summary

    Cisco announced patches for four high‑severity IOS XR CVEs, and Veeam issued a warning for critical RCEs in VBR, but no exploit code or active exploitation is reported.

    00010219
    1.3K followersView on X
  • CVE Brief@DailyCVEBrief
    General

    Full Look Back: three severity scores from one submission, an affected-version range no scanner can read, and why the agreed PR:L predicted the outcome better than the 9.9 did: https://cvebrief.com/cve/cve-2026-21666/ https://t.co/Lu9iDkeZX0

    Post summary

    The tweet references CVE‑2026‑21666 via a link and mentions vague severity scores and version range, but provides no explicit PoC, exploit, active exploitation, patch, or technical details, leading to a General classification with high confidence.

    0000036
    32 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-21666: Veeam Backup Server RCE Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q049zNHn0

    Post summary

    The article announces CVE-2026-21666, an RCE vulnerability in Veeam Backup Server, and promises guidance on response, but does not provide PoC, exploit code, or patch details.

    0000038
    31 followersView on X
  • Technoholic.me@technoholic_me
    Patch

    Veeam released security updates for Backup & Replication to fix critical flaws like CVE-2026-21666 (score 9.9), risking remote code execution. Update now to stay protected. https://thehackernews.com/2026/03/veeam-patches-7-critical-backup.html

    Post summary

    Veeam has issued patches for CVE‑2026‑21666, a high‑score remote code execution vulnerability; users are urged to apply the update promptly.

    0000041
    163 followersView on X
  • IntelHQ@AIIntelHQ
    Patch

    BREAKING: Veeam patches 7 critical vulnerabilities in its Backup & Replication software that could allow attackers to execute remote code, including CVE-2026-21666 with a 9.9 CVSS score, per TechCrunch.

    Post summary

    Veeam has issued patches for seven critical vulnerabilities, including CVE-2026-21666, which poses a remote code execution risk with a 9.9 CVSS score.

    0000045
    5 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Veeam Backup & Replicationに複数の脆弱性 12系と13系で緊急修正(CVE-2026-21666,CVE-2026-21667,CVE-2026-21668) https://rocket-boys.co.jp/security-measures-lab/veeam-backup-replication-flaws-fixed-cve-2026-21666-21667-21668/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The announcement highlights emergency patches for Veeam Backup & Replication to address CVE-2026-21666, CVE-2026-21667, and CVE-2026-21668.

    00000130
    336 followersView on X
  • CyberSec Intel Alliance@CyberAlliance26
    Patch

    🚨 NEW TOP THREAT ALERT (March 15, 2026): Veeam Backup & Replication Multiple Critical RCE Flaws (CVSS up to 9.9, e.g. CVE-2026-21666)! Authenticated domain users can remotely execute code on Backup Servers, manipulate repositories, escalate privileges, and fully compromise enterprise backups. Widespread risk for any org using Veeam. Remediation: Apply Veeam’s latest security updates immediately (check Veeam portal or auto-update). No delays — backups are prime targets. Patch or lose everything! 🔥 #CyberSecurity #VeeamRCE #ZeroDay #BackupSecurity

    Post summary

    The alert highlights critical remote code execution vulnerabilities in Veeam Backup, urges immediate application of the latest security updates to mitigate the risk.

    0000055
    21 followersView on X
  • Dr. John D. Johnson@johndjohnson
    Patch

    Veeam warns of critical flaws exposing backup servers to RCE attacks Three RCE security flaws patched today (tracked as CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669) allow low-privileged domain users to execute remote code on vulnerable backup servers in low-complexity attacks. https://nuel.ink/CrPFlB

    Post summary

    Veeam has released patches for three CVEs (CVE‑2026‑21666, CVE‑2026‑21667, CVE‑2026‑21669) that enable low‑privileged domain users to arbitrarily execute code on backup servers through low‑complexity RCE attacks.

    0000055
    1.1K followersView on X
  • securityrss.ai@securityRSS
    Patch

    Veeam has released updates for critical vulnerabilities in its Backup & Replication software, allowing remote code execution. Key vulnerabilities include CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708 (CVSS score: 9.9), affecting version 12.3.2. https://thehackernews.com/2026/03/veeam-patches-7-critical-backup.html

    Post summary

    Veeam has issued patches addressing three critical remote code execution vulnerabilities (CVE‑2026‑21666, CVE‑2026‑21667, CVE‑2026‑21708) in Backup & Replication 12.3.2 with a CVSS score of 9.9.

    0000044
    78 followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin: Veeam B&R (CVE-2026-21666/21667/21708, CVSS 9.9) allows authenticated RCE on backup servers. Upgrade to 12.3.2.4465 now. #ThreatIntel #RedLeggCTI https://hubs.ly/Q046KMFP0

    Post summary

    The bulletin announces that several Veeam Backup & Replication CVEs allow authenticated RCE (CVSS 9.9) and urges users to upgrade to patch 12.3.2.4465; it does not provide a PoC, exploit code, or evidence of active exploitation.

    0000053
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appveeamveeam_backup_\&_replication---

Explore more