Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708) — Threadlinqs Intelligence
As of 2026-05-30, Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708) is a critical-severity vulnerability threat attributed to FIN7 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0232 · Severity: CRITICAL · CVSS: 9.9 · Status: PATCHED · Category: VULNERABILITY
Attribution: FIN7 · Russia · FINANCIAL
Veeam disclosed 8 security vulnerabilities in Backup & Replication on March 12, 2026, including four critical RCE flaws (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669 at CVSS 9.9, and CVE-2026-21708
On March 12, 2026, Veeam published security advisories KB4830 (v12) and KB4831 (v13) disclosing eight vulnerabilities in Veeam Backup & Replication, their flagship enterprise backup solution. Four of these are rated critical with CVSS 9.9 scores.
The most severe vulnerabilities — CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669 — allow any authenticated domain user to achieve remote code execution on the Veeam Backup Server with low attack complexity and no user interaction required. The scope is changed (S:C), meaning compromise extends beyond the vulnerable component to the broader backup infrastructure. CVE-2026-21708 allows a user with the Backup Viewer role to execute code as the postgres database user, representing a significant privilege boundary violation.
Additional high-severity flaws include CVE-2026-21671 (CVSS 9.1) enabling RCE in high-availability deployments for Backup Administrators, CVE-2026-21668 (CVSS 8.8) allowing arbitrary file manipulation on backup repositories, CVE-2026-21672 (CVSS 8.8) enabling local privilege escalation on Windows servers, and CVE-2026-21670 (CVSS 7.7) permitting extraction of saved SSH credentials.
Veeam Backup & Replication is widely deployed across enterprise environments with over 550,000 customers globally. Backup servers are high-value targets for ransomware operators because destroying or encrypting backups eliminates the victim's recovery capability, increasing ransom payment likelihood. The Veeam Backup Service listens on TCP port 9392, while the REST API operates on TCP port 9401 — both represent network-accessible attack surfaces.
Historically, Veeam vulnerabilities have been rapidly weaponized: CVE-2023-27532 was exploited by FIN7 and Cuba ransomware within weeks of disclosure, and CVE-2024-40711 was leveraged by Akira ransomware operators. Domain-joined Veeam backup servers inherit the risk posture of the Active Directory domain, meaning any compromised domain user account can potentially reach these critical CVSS 9.9 RCE vulnerabilities.
All vulnerabilities were discovered through internal testing or reported via HackerOne. No public proof-of-concept exploits or active exploitation have been confirmed as of March 15, 2026, but the pattern of rapid post-disclosure weaponization for Veeam vulnerabilities makes proactive patching essential. Veeam recommends isolating backup servers from production domains and applying updates to version 12.3.2.4465 (v12) or 13.0.1.2067 (v13) immediately.
Weaknesses (CWE)
CWE-284, CWE-269, CWE-862
Target sectors: enterprise, financial, healthcare, government, critical-infrastructure, technology, education, manufacturing
Target regions: North America, Europe, Asia Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708, CVE-2026-21671, CVE-2026-21668, CVE-2026-21672, CVE-2026-21670, T1190, T1078, T1203, T1059, T1078, T1068, T1078, T1211, T1555, T1552