Data Security, Vulnerability Management, Patch/Configuration Management

Veeam patches critical RCE vulnerabilities in backup software

(Adobe Stock)

Bleeping Computer reports that data protection company Veeam Software has released patches for multiple security flaws within its Backup & Replication solution. The most severe of these are four critical remote code execution (RCE) vulnerabilities that could allow attackers to compromise backup servers.

The vulnerabilities, including three RCE flaws (CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669) and one allowing execution as the postgres user (CVE-2026-21708), enable low-privileged users to execute remote code on vulnerable servers with low complexity. Veeam also addressed high-severity bugs leading to privilege escalation, credential extraction, and arbitrary file manipulation.

These issues were resolved in Veeam Backup & Replication versions 12.3.2.4465 and 13.0.1.2067. The company strongly advises immediate upgrades, as threat actors frequently reverse-engineer patches to target unpatched systems. Veeam Backup & Replication servers are frequent targets for ransomware gangs due to their critical role in data recovery and potential for lateral movement within networks.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds