CVE-2026-21666: Veeam Backup & Replication

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Affected products

  • Veeam Veeam Backup & Replication: from 12.0.0.1402, before 12.3.2.4465 (fixed in 12.3.2.4465)

Published 2026-03-12. Last modified 2026-06-17.