VDB

CVE-2026-21671

CVE-2026-21671 PUBLISHED CVSS 9.100000381469727 CRITICAL

CVE-2026-21666 is a vulnerability in the backup server where an authenticated domain user can perform remote code execution (RCE). CVE-2026-21668 is vulnerability where an authenticated domain user can bypass restrictions and manipulate arbitrary files on the Backup Repository. CVE-2026-21669 is a vulnerability in the backup server where an authenticated domain user can perform remote code execution (RCE). CVE-2026-21670 is a vulnerability allowing where a low-privileged user can extract saved SSH credentials. CVE-2026-21671 is a vulnerability where an authenticated user with the Backup Administrator role can perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. CVE-2026-21672 is a local privilege escalation vulnerability in Windows-based Veeam Backup & Replication servers. CVE-2026-21708 is a vulnerability where an user using Backup Viewer can achieve remote code execution as the postgres user.

EPSS 0.16% · 36.3th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.16%
36.3th percentile

Affected Products

VendorProductVersions
VeeamVeeam Backup & Replication <= 13.0.1.1071
VeeamVeeam Backup & Replication <= 12.3.2.4165

Timeline

  • Mar 12, 2026 CVE Published
  • Mar 12, 2026 PoC Published
  • Mar 12, 2026 PoC Published
  • Mar 12, 2026 PoC Published
  • Mar 12, 2026 PoC Published
  • Mar 12, 2026 PoC Published
  • Mar 12, 2026 PoC Published
  • Mar 12, 2026 PoC Published
  • Mar 13, 2026 EPSS Score
  • Mar 13, 2026 PoC Published
  • Mar 13, 2026 PoC Published
  • Mar 13, 2026 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›