CVE-2026-21708: Veeam Backup & Replication
Critical severity, CVSS 9.9. EPSS: 1.1% chance of exploitation in the next 30 days.
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
Affected products
- Veeam Veeam Backup & Replication: from 12.0.0.1402, before 12.3.2.4465. (fixed in 12.3.2.4465.)
Published 2026-03-12. Last modified 2026-06-17.