Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708)

Veeam Backup & Replication 8 Critical Vulnerabilities (TL-2026-0232), also tracked as Veeam March 2026 Security Advisory, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-03-15. It is attributed to FIN7 (Russia) with medium confidence, affects Veeam Backup & Replication, references 8 CVEs (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669), maps to 18 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-0232

Threat ID
TL-2026-0232
Also known as
Veeam March 2026 Security Advisory, KB4830, KB4831
Severity
CRITICAL
CVSS
9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-03-15
Last reviewed
2026-03-15
Attribution
FIN7
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
enterprise, financial, healthcare, government, critical-infrastructure, technology, education, manufacturing
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in Veeam Backup & Replication 8 Critical Vulnerabilities

Malware and tooling: Akira Ransomware, Cuba Ransomware, BugHatch

Veeam disclosed 8 security vulnerabilities in Backup & Replication on March 12, 2026, including four critical RCE flaws (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669 at CVSS 9.9, and CVE-2026-21708 at CVSS 9.9) that allow low-privileged domain users or Backup Viewer role holders to execute remote code on backup servers. Historical exploitation of Veeam CVEs by FIN7, Cuba, Akira, and BlackBasta ransomware groups makes immediate patching critical.

How Veeam Backup & Replication 8 Critical Vulnerabilities works

On March 12, 2026, Veeam published security advisories KB4830 (v12) and KB4831 (v13) disclosing eight vulnerabilities in Veeam Backup & Replication, their flagship enterprise backup solution. Four of these are rated critical with CVSS 9.9 scores.

The most severe vulnerabilities — CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669 — allow any authenticated domain user to achieve remote code execution on the Veeam Backup Server with low attack complexity and no user interaction required. The scope is changed (S:C), meaning compromise extends beyond the vulnerable component to the broader backup infrastructure. CVE-2026-21708 allows a user with the Backup Viewer role to execute code as the postgres database user, representing a significant privilege boundary violation.

Additional high-severity flaws include CVE-2026-21671 (CVSS 9.1) enabling RCE in high-availability deployments for Backup Administrators, CVE-2026-21668 (CVSS 8.8) allowing arbitrary file manipulation on backup repositories, CVE-2026-21672 (CVSS 8.8) enabling local privilege escalation on Windows servers, and CVE-2026-21670 (CVSS 7.7) permitting extraction of saved SSH credentials.

Veeam Backup & Replication is widely deployed across enterprise environments with over 550,000 customers globally. Backup servers are high-value targets for ransomware operators because destroying or encrypting backups eliminates the victim's recovery capability, increasing ransom payment likelihood. The Veeam Backup Service listens on TCP port 9392, while the REST API operates on TCP port 9401 — both represent network-accessible attack surfaces.

Historically, Veeam vulnerabilities have been rapidly weaponized: CVE-2023-27532 was exploited by FIN7 and Cuba ransomware within weeks of disclosure, and CVE-2024-40711 was leveraged by Akira ransomware operators. Domain-joined Veeam backup servers inherit the risk posture of the Active Directory domain, meaning any compromised domain user account can potentially reach these critical CVSS 9.9 RCE vulnerabilities.

All vulnerabilities were discovered through internal testing or reported via HackerOne. No public proof-of-concept exploits or active exploitation have been confirmed as of March 15, 2026, but the pattern of rapid post-disclosure weaponization for Veeam vulnerabilities makes proactive patching essential. Veeam recommends isolating backup servers from production domains and applying updates to version 12.3.2.4465 (v12) or 13.0.1.2067 (v13) immediately.

MITRE ATT&CK techniques used in TL-2026-0232

credential-access

T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

lateral-movement

T1021 Remote Services; T1210 Exploitation of Remote Services

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071 Application Layer Protocol

defense-evasion

T1078 Valid Accounts; T1211 Exploitation for Stealth

initial-access

T1190 Exploit Public-Facing Application

collection

T1213 Data from Information Repositories

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Affected products and versions in Veeam Backup & Replication 8 Critical Vulnerabilities

  • Veeam — Backup & Replication
    Vulnerable versions: 12.3.2.4165 and all earlier v12 builds; 13.0.1.1071 and all earlier v13 builds
    Fixed in: 12.3.2.4465 (v12); 13.0.1.2067 (v13)

Remediation for Veeam Backup & Replication 8 Critical Vulnerabilities

Patches

  • Veeam Backup & Replication v12: Install build 12.3.2.4465 (KB4830)
  • Veeam Backup & Replication v13: Install build 13.0.1.2067 (KB4831)

Immediate actions

  • Upgrade Veeam Backup & Replication v12 to build 12.3.2.4465 or later
  • Upgrade Veeam Backup & Replication v13 to build 13.0.1.2067 or later
  • Restrict network access to Veeam Backup Server ports TCP 9392 and 9401 to authorized management stations only
  • Audit domain user accounts with access to Veeam infrastructure and remove unnecessary permissions
  • Review and restrict Backup Viewer role assignments to essential personnel only
  • Monitor for anomalous authentication attempts to Veeam Backup Server services

Workarounds

  • If immediate patching is not possible, restrict all network access to Veeam Backup Server to only authorized admin workstations via firewall rules
  • Disable REST API (port 9401) if not actively used
  • Remove all non-essential domain user accounts from Veeam roles
  • Temporarily disconnect Veeam Backup Server from domain if feasible in the environment

Longer-term hardening

  • Remove Veeam Backup Servers from production Active Directory domains — deploy in separate management forest or workgroup
  • Implement network segmentation isolating backup infrastructure from general user network segments
  • Deploy EDR with behavioral detection on all Veeam Backup Server hosts
  • Enable multi-factor authentication for Veeam console and API access
  • Implement immutable backup repositories to prevent ransomware from destroying recovery data
  • Establish regular vulnerability scanning cadence for backup infrastructure
  • Implement SIEM alerting for suspicious activity on Veeam service ports

CVEs associated with Veeam Backup & Replication 8 Critical Vulnerabilities

CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708, CVE-2026-21671, CVE-2026-21668, CVE-2026-21672, CVE-2026-21670

Weaknesses (CWE) in Veeam Backup & Replication 8 Critical Vulnerabilities

CWE-284, CWE-269, CWE-862

Timeline of Veeam Backup & Replication 8 Critical Vulnerabilities

  • CVE-2023-27532 disclosed in Veeam Backup & Replication — unauthenticated credential extraction via TCP 9401, later exploited by FIN7 and Cuba ransomware
  • Cuba ransomware group observed actively exploiting CVE-2023-27532 against US critical infrastructure organizations
  • CVE-2024-40711 disclosed — pre-authentication RCE in Veeam, subsequently exploited by Akira ransomware operators
  • BleepingComputer, The Hacker News, Arctic Wolf, SOCRadar, and CSO Online publish advisories warning of critical Veeam RCE flaws
  • NVD publishes CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708, CVE-2026-21668, CVE-2026-21670, CVE-2026-21671, CVE-2026-21672
  • Veeam releases patched builds 12.3.2.4465 (v12) and 13.0.1.2067 (v13) to address all 8 vulnerabilities
  • Veeam publishes security advisories KB4830 (v12) and KB4831 (v13) disclosing 8 vulnerabilities including 4 critical CVSS 9.9 RCEs
  • Penligent and runZero publish deep technical analysis of the Veeam vulnerability cluster and asset discovery guidance
  • No public PoC exploits or confirmed active exploitation as of this date; EPSS probability remains low at 0.00366
  • As of 2026-05-29, all 8 Veeam Backup & Replication CVEs (incl. CVE-2026-21666, CVSS 9.9) remain fixed in builds 12.3.2.4465/13.0.1.2067, with no public PoC, no confirmed in-the-wild exploitation, and no CISA KEV listing per NVD, SOCRadar, Greenbone and Hacker News. PATCHED status holds; monitoring is warranted given Veeam's history of rapid ransomware weaponization.

Sources cited for Veeam Backup & Replication 8 Critical Vulnerabilities

Threats related to Veeam Backup & Replication 8 Critical Vulnerabilities

Detection coverage for TL-2026-0232

As of 2026-03-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0232 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats