CVE-2026-21667Disclosure(veeam / veeam_backup_\&_replication)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch veeam veeam_backup_\&_replication systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • veeam_backup_\&_replication

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 7 mentions (2026-03-13); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
veeam_backup_\&_replication

Deep dive

Activity timeline12 mentions / 5d
02457Mentions · 2026-03-12: 2Mentions · 2026-03-13: 7Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-13: 4Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 6Technical Details · 2026-03-14: 1Technical Details · 2026-03-18: 103-1203-1303-1403-1603-18
Signal classification2 categories
Disclosure
758.3%
Patch
541.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-03-137
Disclosure4Patch3
2026-03-141
Patch1
2026-03-161
Patch1
2026-03-181
Disclosure1
Full discourse12 posts
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na sérii RCE zranitelností ve Veeam Backup and Replication, CVE-2026-21666, CVE-2026-21667, CVE-2026-21668 a další. V produktu Veeam Backup & Replication byla identifikována série kritických a vysoce závažných zranitelností. Úspěšné zneužití těchto zranitelností by mohlo umožnit ověřeným uživatelům nebo útočníkům s nízkými oprávněními spustit libovolný kód, eskalovat oprávnění, obejít bezpečnostní omezení, manipulovat se soubory úložiště nebo extrahovat uložené přihlašovací údaje. Zranitelnosti postihují všechny produkty Veeam Backup and Replication do verze 12.3.2.4165 a 13.0.1.1071. 📌Doporučujeme aktualizovat na verzi 12.3.2.4465 nebo 13.0.1.2067.

    Post summary

    Veeam Backup & Replication is affected by a series of critical RCE vulnerabilities (CVE-2026-21666–68) that could let authenticated or low‑privilege attackers execute arbitrary code; patches are available for affected versions.

    03050978
    4.2K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Veeam warns of critical flaws exposing backup servers to RCE attacks https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/ 『(直訳) RCE セキュリティ脆弱性 ( CVE-2026-21666、CVE-2026-21667、CVE-2026-21669として追跡) により、低い権限を持つドメイン ユーザーが、複雑度の低い攻撃で脆弱なバックアップ サーバー上でリモート コードを実行できるようになります。4 番目の脆弱性 ( CVE-2026-21708として追跡) により、バックアップ ビューアーが postgres ユーザーとしてリモート コード実行を取得できるようになります。』

    Post summary

    Veeam has disclosed several critical RCE CVEs that allow low‑privilege domain users to execute code on backup servers, with detailed technical information but no evidence of active exploitation or publicly available PoCs.

    100311.2K
    11.4K followersView on X
  • maruomosquit@maru1151157
    Disclosure

    🚨 CVE-2026-21667 (CVSS: 9.9) 認証されたドメインユーザーがバックアップサーバーにリモートコード実行(RCE)を可能にする脆弱性。 https://maruomosquit.com/vulnerability/CVE-2026-21667/ #脆弱性 #セキュリティ

    Post summary

    The tweet announces CVE‑2026‑21667, highlights its high severity and RCE impact, but does not provide PoC, exploit code, active exploitation evidence, or patch details.

    0001096
    1.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Veeam released update 12.3.2.4465 fixing seven security flaws in Backup & Replication, including critical RCE bugs CVE-2026-21666 and CVE-2026-21667 with a 9.9 severity score. #BackupSecurity #RCEVulnerabilities #USA https://ift.tt/HRU3XWP

    Post summary

    Veeam issued update 12.3.2.4465 to patch seven critical RCE vulnerabilities (CVE-2026-21666, CVE-2026-21667) rated at a 9.9 severity score.

    00010171
    3.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Veeam Backup & Replicationに複数の脆弱性 12系と13系で緊急修正(CVE-2026-21666,CVE-2026-21667,CVE-2026-21668) https://rocket-boys.co.jp/security-measures-lab/veeam-backup-replication-flaws-fixed-cve-2026-21666-21667-21668/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The announcement confirms that emergency patches have been released for CVE-2026-21666, CVE-2026-21667, and CVE-2026-21668 in Veeam Backup & Replication 12 and 13, but provides no technical exploitation details or PoC information.

    00000130
    336 followersView on X
  • Dr. John D. Johnson@johndjohnson
    Patch

    Veeam warns of critical flaws exposing backup servers to RCE attacks Three RCE security flaws patched today (tracked as CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669) allow low-privileged domain users to execute remote code on vulnerable backup servers in low-complexity attacks. https://nuel.ink/CrPFlB

    Post summary

    Veeam has issued a patch for three RCE CVEs (2026‑21666, 2026‑21667, 2026‑21669) that allow low‑privileged domain users to run remote code on backup servers; the advisory emphasizes the need to apply the available fix.

    0000055
    1.1K followersView on X
  • securityrss.ai@securityRSS
    Patch

    Veeam has released updates for critical vulnerabilities in its Backup & Replication software, allowing remote code execution. Key vulnerabilities include CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708 (CVSS score: 9.9), affecting version 12.3.2. https://thehackernews.com/2026/03/veeam-patches-7-critical-backup.html

    Post summary

    Veeam has issued patches for three critical CVEs (CVE‑2026‑21666, CVE‑2026‑21667, CVE‑2026‑21708) that allow remote code execution with a high CVSS score of 9.9 affecting version 12.3.2.

    0000044
    78 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 CVE-2026-21666 CVE-2026-21667 CVE-2026-21668 CVE-2026-21672 CVE-2026-21708 KB4830: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4465 https://www.veeam.com/kb4830

    Post summary

    The post lists several CVE identifiers and references a Veeam knowledge base article announcing that these vulnerabilities have been resolved in version 12.3.2.4465.

    00000322
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21667 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. https://www.cve.org/CVERecord?id=CVE-2026-21667

    Post summary

    The post announces CVE-2026-21667, noting it allows authenticated domain users to execute remote code on a backup server, but offers no PoC, exploit, or remedy details.

    00000172
    56.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-21667 PT-Identifier: PT-2026-24953 Vendor: Veeam Product: Backup and Replication CVSS: 10.0 Credits: n/a Description: A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21667 • https://www.veeam.com/kb4830 #dbugs_vuln

    Post summary

    Veeam’s Backup and Replication is affected by CVE‑2026‑21667, an authenticated remote code execution vulnerability with a CVSS of 10.0, but the post contains no proof‑of‑concept, exploit code, or evidence of active exploitation.

    0000058
    593 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-21667 - Critical A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. https://www.thehackerwire.com/vulnerability/CVE-2026-21667/ https://t.co/aPycu2SNbj

    Post summary

    CVE-2026-21667 is a remote code execution vulnerability affecting Backup Server users with domain authentication, disclosed with basic technical details but lacking PoC, exploit code, or evidence of active exploitation.

    0000052
    134 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-21667: CRITICAL] A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.#cve,CVE-2026-21667,#cybersecurity https://cvefind.com/CVE-2026-21667

    Post summary

    A newly discovered CVE-2026-21667 is a critical remote code execution vulnerability for authenticated domain users on backup servers, but no PoC, exploit, patch, or active exploitation information was provided.

    0000058
    601 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appveeamveeam_backup_\&_replication---

Explore more