CVE-2026-21671: Veeam Backup & Replication

Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

Affected products

  • Veeam Veeam Backup & Replication: from 13.0.0.496, up to and including 13.0.1.1071

Published 2026-03-12. Last modified 2026-06-17.