CVE-2026-21708Disclosure(veeam / veeam_backup_\&_replication)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch veeam veeam_backup_\&_replication systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • veeam_backup_\&_replication

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 8 mentions (2026-03-13); latest day: 1
  • 14 total mentions across 3 days

Affected systems

Vendors
Products
veeam_backup_\&_replication

Deep dive

Activity timeline14 mentions / 3d
02468Mentions · 2026-03-12: 5Mentions · 2026-03-13: 8Mentions · 2026-03-20: 1PoC Mentioned / Linked · 2026-03-12: 1Patch / Workaround · 2026-03-13: 7Technical Details · 2026-03-12: 5Technical Details · 2026-03-13: 503-1203-1303-20
Signal classification3 categories
Disclosure
642.9%
Patch
642.9%
General
214.3%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-125
Disclosure5
2026-03-138
Disclosure1General1Patch6
2026-03-201
General1
Full discourse14 posts
  • Gray Hats@the_yellow_fall
    Patch

    Veeam releases a critical security update fixing 9.9 CVSS RCE flaws (CVE-2026-21669, CVE-2026-21708) in Backup & Replication. Patch servers immediately. https://securityonline.info/veeam-urgently-patches-critical-9-9-cvss-rce-flaws-in-backup-servers/ https://t.co/u1XS0qtQHg

    Post summary

    Veeam has released a critical update that addresses two high‑severity CVE‑2026‑21669 and CVE‑2026‑21708 RCE flaws in its Backup & Replication product, and users are urged to apply the patch immediately.

    040151800
    10.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Veeam urgently patches critical 9.9 CVSS RCE flaws (CVE-2026-21666, CVE-2026-21708) in Backup & Replication 12.3.2. Update your servers immediately. #Veeam #CVE #CyberSecurity #InfoSec #RCE #BackupSecurity #PatchAlert #Vulnerability #TechNews https://securityonline.info/total-takeover-veeam-patches-critical-9-9-cvss-rce-flaws-in-backup-replication-12-3-2/

    Post summary

    The message announces Veeam’s urgent patch for two critical RCE flaws (CVE‑2026‑21666, CVE‑2026‑21708) with CVSS 9.9, urging immediate update of Backup & Replication 12.3.2.

    130102873
    10.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 CVE-2026-21669 CVE-2026-21670 CVE-2026-21671 CVE-2026-21672 CVE-2026-21708 KB4831: Vulnerabilities Resolved in Veeam Backup & Replication 13.0.1.2067 https://www.veeam.com/kb4831

    Post summary

    The post lists several CVE-2026 identifiers and notes that Veeam KB4831 resolves them in version 13.0.1.2067.

    00001330
    6.7K followersView on X
  • ANONHAVEN@anonhaven_com
    Patch

    Veeam patches two CVSS 9.9 RCE flaws. CVE-2026-21669: authenticated domain user → full RCE CVE-2026-21708: Backup Viewer → RCE as postgres Update to 13.0.1.2067 immediately. Backup servers are ransomware entry points. #Veeam #RCE #InfoSec #PatchNow https://anonhaven.com/en/news/veeam-patches-four-cvss-99-flaws-in-backup-and-replication-software/

    Post summary

    Veeam released an update (13.0.1.2067) to patch two high‑severity RCE CVEs—CVE‑2026‑21669 and CVE‑2026‑21708—with no evidence of current exploitation.

    0001060
    10 followersView on X
  • dbugs@ptdbugs
    Patch

    CVE: CVE-2026-21708 Vendor: Veeam Product: Backup and Recovery CVSS: 10.0 Credits: n/a Description: A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21708 • https://www.veeam.com/kb4831 • https://www.veeam.com/kb4830 #dbugs_vuln

    Post summary

    A critical (CVSS 10.0) remote code execution flaw in Veeam Backup & Recovery allows a Backup Viewer to run code as the postgres user; vendor KB references suggest a patch is available.

    0000174
    593 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-21708: Veeam Backup Viewer RCE Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q047JXKk0

    Post summary

    The provided text only names the CVE and includes a link; no specific details about PoC, exploit, active use, patch, technical aspects, or debunking are conveyed.

    0000032
    29 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Veeam ❗ CVE-2026-21708 ❗ CVE-2026-21671 ❗ CVE-2026-21669 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-veeam-5/ https://t.co/VOaE5dL6x3

    Post summary

    The post simply lists several CVE identifiers related to Veeam products and directs readers to external links for more information, without providing details on exploitation or remediation.

    00000106
    6.6K followersView on X
  • securityrss.ai@securityRSS
    Patch

    Veeam has released updates for critical vulnerabilities in its Backup & Replication software, allowing remote code execution. Key vulnerabilities include CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708 (CVSS score: 9.9), affecting version 12.3.2. https://thehackernews.com/2026/03/veeam-patches-7-critical-backup.html

    Post summary

    Veeam released patches for three critical CVEs—CVE-2026-21666, CVE-2026-21667, and CVE-2026-21708—with a CVSS score of 9.9, addressing remote code execution vulnerabilities in version 12.3.2.

    0000044
    78 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 CVE-2026-21666 CVE-2026-21667 CVE-2026-21668 CVE-2026-21672 CVE-2026-21708 KB4830: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4465 https://www.veeam.com/kb4830

    Post summary

    Veeam KB 4830 lists several CVEs (CVE-2026-21666, 21667, 21668, 21672, 21708) that have been resolved in version 12.3.2.4465; no exploit or technical details are provided.

    00000322
    6.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21708 A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. https://www.cve.org/CVERecord?id=CVE-2026-21708

    Post summary

    CVE‑2026‑21708 is a newly disclosed RCE vulnerability in Backup Viewer that allows execution as the postgres user, with no evidence of active exploitation, PoC, or patch details.

    00000188
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21708 Remote Code Execution in Backup Viewer Targeting PostgreSQL User https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21708

    Post summary

    The text announces CVE-2026‑21708 as a remote code execution flaw in the Backup Viewer that targets PostgreSQL users.

    0000029
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-21708: CRITICAL] A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.#cve,CVE-2026-21708,#cybersecurity https://cvefind.com/CVE-2026-21708

    Post summary

    The post announces CVE-2026-21708 as a critical RCE vulnerability in Backup Viewer that allows execution as the postgres user, but does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    0000060
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-21708 - Critical A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. https://www.thehackerwire.com/vulnerability/CVE-2026-21708/ https://t.co/pknMet0lGP

    Post summary

    The tweet announces the critical CVE-2026-21708 vulnerability, noting it allows a Backup Viewer to execute code as the postgres user; it provides basic technical detail but no information on patches, PoC, or active exploitation.

    0000053
    134 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-21708: Veeam (CVSS: 10.0)... Perfect 10.0 CVSS with low-privilege Backup Viewer escalating to postgres RCE - Veeam's backup infra just became the cr... https://zerodaysignal.com/vulnerability/CVE-2026-21708 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces Veeam vulnerability CVE‑2026‑21708 (CVSS 10.0) permitting low‑privilege Backup Viewer escalation to postgreSQL RCE, with details hosted on ZeroDaySignal.

    0000077
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appveeamveeam_backup_\&_replication---

Explore more