CVE-2026-21671
CVE-2026-21666 is a vulnerability in the backup server where an authenticated domain user can perform remote code execution (RCE). CVE-2026-21668 is vulnerability where an authenticated domain user can bypass restrictions and manipulate arbitrary files on the Backup Repository. CVE-2026-21669 is a vulnerability in the backup server where an authenticated domain user can perform remote code execution (RCE). CVE-2026-21670 is a vulnerability allowing where a low-privileged user can extract saved SSH credentials. CVE-2026-21671 is a vulnerability where an authenticated user with the Backup Administrator role can perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. CVE-2026-21672 is a local privilege escalation vulnerability in Windows-based Veeam Backup & Replication servers. CVE-2026-21708 is a vulnerability where an user using Backup Viewer can achieve remote code execution as the postgres user.
EPSS 0.16% · 36.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Veeam | Veeam Backup & Replication <= 13.0.1.1071 | |
| Veeam | Veeam Backup & Replication <= 12.3.2.4165 |
Timeline
- Mar 12, 2026 CVE Published
- Mar 12, 2026 PoC Published
- Mar 12, 2026 PoC Published
- Mar 12, 2026 PoC Published
- Mar 12, 2026 PoC Published
- Mar 12, 2026 PoC Published
- Mar 12, 2026 PoC Published
- Mar 12, 2026 PoC Published
- Mar 13, 2026 EPSS Score
- Mar 13, 2026 PoC Published
- Mar 13, 2026 PoC Published
- Mar 13, 2026 PoC Published
References
- https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-veeam-backup-replication-patch-immediately advisory
- https://www.veeam.com/kb4830 vendor
- https://www.veeam.com/kb4831 vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-21666 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21668 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21669 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21670 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21671 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21672 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-21708 technical