CVE-2026-21669Disclosure(veeam / veeam_backup_\&_replication)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch veeam veeam_backup_\&_replication systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • veeam_backup_\&_replication

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 6 mentions (2026-03-13); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
veeam_backup_\&_replication

Deep dive

Activity timeline9 mentions / 3d
02356Mentions · 2026-03-12: 2Mentions · 2026-03-13: 6Mentions · 2026-03-14: 1Patch / Workaround · 2026-03-13: 3Patch / Workaround · 2026-03-14: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 4Technical Details · 2026-03-14: 103-1203-1303-14
Signal classification3 categories
Disclosure
444.4%
Patch
444.4%
General
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-03-136
Disclosure2General1Patch3
2026-03-141
Patch1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    Veeam releases a critical security update fixing 9.9 CVSS RCE flaws (CVE-2026-21669, CVE-2026-21708) in Backup & Replication. Patch servers immediately. https://securityonline.info/veeam-urgently-patches-critical-9-9-cvss-rce-flaws-in-backup-servers/ https://t.co/u1XS0qtQHg

    Post summary

    Veeam has released a critical patch for two CVE‑2026‑21669 and CVE‑2026‑21708 RCE vulnerabilities, reminding administrators to apply the update immediately.

    040151800
    10.6K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 CVE-2026-21669 CVE-2026-21670 CVE-2026-21671 CVE-2026-21672 CVE-2026-21708 KB4831: Vulnerabilities Resolved in Veeam Backup & Replication 13.0.1.2067 https://www.veeam.com/kb4831

    Post summary

    The post lists several CVE identifiers and references a Veeam KB article that indicates these vulnerabilities have been resolved in a newer product version, with no further exploitation or technical detail provided.

    00001330
    6.7K followersView on X
  • ANONHAVEN@anonhaven_com
    Patch

    Veeam patches two CVSS 9.9 RCE flaws. CVE-2026-21669: authenticated domain user → full RCE CVE-2026-21708: Backup Viewer → RCE as postgres Update to 13.0.1.2067 immediately. Backup servers are ransomware entry points. #Veeam #RCE #InfoSec #PatchNow https://anonhaven.com/en/news/veeam-patches-four-cvss-99-flaws-in-backup-and-replication-software/

    Post summary

    Veeam released a patch for two high‑severity (CVSS 9.9) RCE flaws (CVE‑2026‑21669 & CVE‑2026‑21708) and urges administrators to upgrade immediately to 13.0.1.2067.

    0001060
    10 followersView on X
  • Dr. John D. Johnson@johndjohnson
    Patch

    Veeam warns of critical flaws exposing backup servers to RCE attacks Three RCE security flaws patched today (tracked as CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669) allow low-privileged domain users to execute remote code on vulnerable backup servers in low-complexity attacks. https://nuel.ink/CrPFlB

    Post summary

    Veeam reports that three newly patched RCE vulnerabilities (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669) would allow low‑privileged domain users to execute remote code on backup servers, underscoring the importance of applying the latest fixes.

    0000055
    1.1K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Veeam ❗ CVE-2026-21708 ❗ CVE-2026-21671 ❗ CVE-2026-21669 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-veeam-5/ https://t.co/VOaE5dL6x3

    Post summary

    The tweet lists three Veeam CVEs and links to external sources for additional information, but provides no PoC, exploit details, patch notices, or technical depth.

    00000106
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21669 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. https://www.cve.org/CVERecord?id=CVE-2026-21669

    Post summary

    The entry details a new CVE (CVE-2026-21669) that enables authenticated domain users to execute code remotely on a Backup Server, with technical specifics provided but no exploit, patch, or active exploitation mention.

    00000157
    56.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE: CVE-2026-21669 PT-Identifier: PT-2026-24955 Vendor: Veeam Product: Backup and Replication CVSS: 10.0 Credits: n/a Description: A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21669 • https://www.veeam.com/kb4831 #dbugs_vuln

    Post summary

    CVE‑2026‑21669 is a high‑severity RCE flaw in Veeam Backup and Replication that allows authenticated domain users to execute code remotely; no PoC, exploit, or active exploitation is reported, and the post only references a Veeam KB article that may contain mitigation information.

    0000060
    593 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-21669 - Critical A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. https://www.thehackerwire.com/vulnerability/CVE-2026-21669/ https://t.co/h6bR9qep0q

    Post summary

    CVE-2026-21669 is a newly disclosed RCE vulnerability affecting a Backup Server that requires authenticated domain users. The tweet provides only a brief description and link to an article, with no evidence of PoC, exploit, active use, or patch information.

    0000046
    134 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-21669: CRITICAL] A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.#cve,CVE-2026-21669,#cybersecurity https://cvefind.com/CVE-2026-21669

    Post summary

    A critical RCE vulnerability (CVE‑2026‑21669) affecting authenticated domain users on a backup server is disclosed, with basic technical details provided but no PoC, exploitation activity, or patch mention.

    0000061
    601 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appveeamveeam_backup_\&_replication---

Explore more