Vulnerabilities · 186 days ago
The issues allow low-privileged domain users and a Backup Viewer role to execute code on backup servers.
CVEs in this update
7 CVEs
5 critical · 2 high · 0 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-21666 · 9.9 CRITICAL
2 sources covering this story
Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution
Veeam fixes 7 Backup & Replication flaws, including CVSS 9.9 RCE bugs, warning attackers may exploit unpatched systems.
Veeam warns of critical flaws exposing backup servers to RCE attacks
Data protection company Veeam Software has patched multiple flaws in its Backup & Replication solution, including four critical remote code execution (RCE) vulnerabilities.
Part of the PlainSec briefing for 2026-03-14