CVE-2026-21709: Veeam Backup And Replication

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.

Affected products

  • Veeam Backup And Replication: from 12, before 12.3.2 (fixed in 12.3.2)
  • Veeam Software Appliance: from 13, before 13.0.1 (fixed in 13.0.1)

Published 2026-04-17. Last modified 2026-06-17.