CVE-2026-21672: Veeam Backup And Replication

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

Affected products

  • Veeam Backup And Replication: from 12, before 12.3.2 (fixed in 12.3.2); from 13, before 13.0.1 (fixed in 13.0.1)

Published 2026-03-12. Last modified 2026-06-17.