CVE-2026-21668Disclosure(veeam / veeam_backup_\&_replication)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch veeam veeam_backup_\&_replication systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • veeam_backup_\&_replication

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-13); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
veeam_backup_\&_replication

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-12: 2Mentions · 2026-03-13: 4Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 303-1203-1303-16
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-03-134
Disclosure2Patch2
2026-03-161
Patch1
Full discourse7 posts
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na sérii RCE zranitelností ve Veeam Backup and Replication, CVE-2026-21666, CVE-2026-21667, CVE-2026-21668 a další. V produktu Veeam Backup & Replication byla identifikována série kritických a vysoce závažných zranitelností. Úspěšné zneužití těchto zranitelností by mohlo umožnit ověřeným uživatelům nebo útočníkům s nízkými oprávněními spustit libovolný kód, eskalovat oprávnění, obejít bezpečnostní omezení, manipulovat se soubory úložiště nebo extrahovat uložené přihlašovací údaje. Zranitelnosti postihují všechny produkty Veeam Backup and Replication do verze 12.3.2.4165 a 13.0.1.1071. 📌Doporučujeme aktualizovat na verzi 12.3.2.4465 nebo 13.0.1.2067.

    Post summary

    The advisory announces critical RCE vulnerabilities (CVE‑2026‑21666/67/68) in Veeam Backup & Replication that enable attackers to run arbitrary code, elevate privileges, and steal credentials, and urges users to update to the patched 12.3.2.4465 or 13.0.1.2067 releases.

    03050978
    4.2K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Veeam Backup & Replicationに複数の脆弱性 12系と13系で緊急修正(CVE-2026-21666,CVE-2026-21667,CVE-2026-21668) https://rocket-boys.co.jp/security-measures-lab/veeam-backup-replication-flaws-fixed-cve-2026-21666-21667-21668/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The tweet announces an urgent patch for the CVE-2026-21666, CVE-2026-21667, and CVE-2026-21668 vulnerabilities affecting Veeam Backup & Replication.

    00000130
    336 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 CVE-2026-21666 CVE-2026-21667 CVE-2026-21668 CVE-2026-21672 CVE-2026-21708 KB4830: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4465 https://www.veeam.com/kb4830

    Post summary

    The tweet lists several CVE identifiers and states they have been resolved in Veeam Backup & Replication 12.3.2.4465, linking to a KB article for details.

    00000322
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21668 A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. https://www.cve.org/CVERecord?id=CVE-2026-21668

    Post summary

    A new CVE, CVE-2026-21668, is disclosed as allowing an authenticated domain user to bypass restrictions and modify arbitrary files in a Backup Repository. No proof of concept, exploitation, patch, or false-positive claim is provided.

    00000147
    56.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-21668 PT-Identifier: PT-2026-24954 Vendor: Veeam Product: Backup and Replication CVSS: 8.8 Credits: n/a Description: A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21668 • https://www.veeam.com/kb4830 #dbugs_vuln

    Post summary

    The post announces CVE-2026-21668, a privilege‑elevation and arbitrary file manipulation flaw in Veeam Backup and Replication, noting its CVSS score but providing no PoC, exploit code, or evidence of active exploitation.

    0000056
    593 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-21668 - High A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. https://www.thehackerwire.com/vulnerability/CVE-2026-21668/ https://t.co/J4A3B2Jpdr

    Post summary

    The tweet announces CVE-2026-21668, a high‑severity vulnerability that allows authenticated domain users to bypass restrictions and manipulate files on a backup repository. No additional details on PoC, exploit, patch, or active exploitation are provided.

    0000031
    134 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-21668: HIGH] A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.#cve,CVE-2026-21668,#cybersecurity https://cvefind.com/CVE-2026-21668

    Post summary

    A high‑severity vulnerability allows authenticated domain users to bypass restrictions and modify arbitrary files on a backup repository. No PoC, exploit, or patch is referenced.

    0000038
    601 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appveeamveeam_backup_\&_replication---

Explore more