Bleeping Computer reports that data protection company Veeam Software has released patches for multiple security flaws within its Backup & Replication solution. The most severe of these are four critical remote code execution (RCE) vulnerabilities that could allow attackers to compromise backup servers.The vulnerabilities, including three RCE flaws (CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669) and one allowing execution as the postgres user (CVE-2026-21708), enable low-privileged users to execute remote code on vulnerable servers with low complexity. Veeam also addressed high-severity bugs leading to privilege escalation, credential extraction, and arbitrary file manipulation.These issues were resolved in Veeam Backup & Replication versions 12.3.2.4465 and 13.0.1.2067. The company strongly advises immediate upgrades, as threat actors frequently reverse-engineer patches to target unpatched systems. Veeam Backup & Replication servers are frequent targets for ransomware gangs due to their critical role in data recovery and potential for lateral movement within networks.Source: Bleeping Computer
Data Security, Vulnerability Management, Patch/Configuration Management
Veeam patches critical RCE vulnerabilities in backup software
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
