Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708)
Veeam Backup & Replication 8 Critical Vulnerabilities (TL-2026-0232), also tracked as Veeam March 2026 Security Advisory, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-03-15. It is attributed to FIN7 (Russia) with medium confidence, affects Veeam Backup & Replication, references 8 CVEs (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669), maps to 18 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-0232
- Threat ID
- TL-2026-0232
- Also known as
- Veeam March 2026 Security Advisory, KB4830, KB4831
- Severity
- CRITICAL
- CVSS
- 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-03-15
- Last reviewed
- 2026-03-15
- Attribution
- FIN7
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- enterprise, financial, healthcare, government, critical-infrastructure, technology, education, manufacturing
- Target regions
- North America, Europe, Asia Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Veeam Backup & Replication 8 Critical Vulnerabilities
Malware and tooling: Akira Ransomware, Cuba Ransomware, BugHatch
Veeam disclosed 8 security vulnerabilities in Backup & Replication on March 12, 2026, including four critical RCE flaws (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669 at CVSS 9.9, and CVE-2026-21708 at CVSS 9.9) that allow low-privileged domain users or Backup Viewer role holders to execute remote code on backup servers. Historical exploitation of Veeam CVEs by FIN7, Cuba, Akira, and BlackBasta ransomware groups makes immediate patching critical.
How Veeam Backup & Replication 8 Critical Vulnerabilities works
On March 12, 2026, Veeam published security advisories KB4830 (v12) and KB4831 (v13) disclosing eight vulnerabilities in Veeam Backup & Replication, their flagship enterprise backup solution. Four of these are rated critical with CVSS 9.9 scores.
The most severe vulnerabilities — CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669 — allow any authenticated domain user to achieve remote code execution on the Veeam Backup Server with low attack complexity and no user interaction required. The scope is changed (S:C), meaning compromise extends beyond the vulnerable component to the broader backup infrastructure. CVE-2026-21708 allows a user with the Backup Viewer role to execute code as the postgres database user, representing a significant privilege boundary violation.
Additional high-severity flaws include CVE-2026-21671 (CVSS 9.1) enabling RCE in high-availability deployments for Backup Administrators, CVE-2026-21668 (CVSS 8.8) allowing arbitrary file manipulation on backup repositories, CVE-2026-21672 (CVSS 8.8) enabling local privilege escalation on Windows servers, and CVE-2026-21670 (CVSS 7.7) permitting extraction of saved SSH credentials.
Veeam Backup & Replication is widely deployed across enterprise environments with over 550,000 customers globally. Backup servers are high-value targets for ransomware operators because destroying or encrypting backups eliminates the victim's recovery capability, increasing ransom payment likelihood. The Veeam Backup Service listens on TCP port 9392, while the REST API operates on TCP port 9401 — both represent network-accessible attack surfaces.
Historically, Veeam vulnerabilities have been rapidly weaponized: CVE-2023-27532 was exploited by FIN7 and Cuba ransomware within weeks of disclosure, and CVE-2024-40711 was leveraged by Akira ransomware operators. Domain-joined Veeam backup servers inherit the risk posture of the Active Directory domain, meaning any compromised domain user account can potentially reach these critical CVSS 9.9 RCE vulnerabilities.
All vulnerabilities were discovered through internal testing or reported via HackerOne. No public proof-of-concept exploits or active exploitation have been confirmed as of March 15, 2026, but the pattern of rapid post-disclosure weaponization for Veeam vulnerabilities makes proactive patching essential. Veeam recommends isolating backup servers from production domains and applying updates to version 12.3.2.4465 (v12) or 13.0.1.2067 (v13) immediately.
MITRE ATT&CK techniques used in TL-2026-0232
credential-access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
discovery
T1018 Remote System Discovery; T1046 Network Service Discovery
lateral-movement
T1021 Remote Services; T1210 Exploitation of Remote Services
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol
defense-evasion
T1078 Valid Accounts; T1211 Exploitation for Stealth
initial-access
T1190 Exploit Public-Facing Application
collection
T1213 Data from Information Repositories
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Affected products and versions in Veeam Backup & Replication 8 Critical Vulnerabilities
- Veeam — Backup & Replication
Vulnerable versions: 12.3.2.4165 and all earlier v12 builds; 13.0.1.1071 and all earlier v13 builds
Fixed in: 12.3.2.4465 (v12); 13.0.1.2067 (v13)
Remediation for Veeam Backup & Replication 8 Critical Vulnerabilities
Patches
- Veeam Backup & Replication v12: Install build 12.3.2.4465 (KB4830)
- Veeam Backup & Replication v13: Install build 13.0.1.2067 (KB4831)
Immediate actions
- Upgrade Veeam Backup & Replication v12 to build 12.3.2.4465 or later
- Upgrade Veeam Backup & Replication v13 to build 13.0.1.2067 or later
- Restrict network access to Veeam Backup Server ports TCP 9392 and 9401 to authorized management stations only
- Audit domain user accounts with access to Veeam infrastructure and remove unnecessary permissions
- Review and restrict Backup Viewer role assignments to essential personnel only
- Monitor for anomalous authentication attempts to Veeam Backup Server services
Workarounds
- If immediate patching is not possible, restrict all network access to Veeam Backup Server to only authorized admin workstations via firewall rules
- Disable REST API (port 9401) if not actively used
- Remove all non-essential domain user accounts from Veeam roles
- Temporarily disconnect Veeam Backup Server from domain if feasible in the environment
Longer-term hardening
- Remove Veeam Backup Servers from production Active Directory domains — deploy in separate management forest or workgroup
- Implement network segmentation isolating backup infrastructure from general user network segments
- Deploy EDR with behavioral detection on all Veeam Backup Server hosts
- Enable multi-factor authentication for Veeam console and API access
- Implement immutable backup repositories to prevent ransomware from destroying recovery data
- Establish regular vulnerability scanning cadence for backup infrastructure
- Implement SIEM alerting for suspicious activity on Veeam service ports
CVEs associated with Veeam Backup & Replication 8 Critical Vulnerabilities
CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708, CVE-2026-21671, CVE-2026-21668, CVE-2026-21672, CVE-2026-21670
Weaknesses (CWE) in Veeam Backup & Replication 8 Critical Vulnerabilities
CWE-284, CWE-269, CWE-862
Timeline of Veeam Backup & Replication 8 Critical Vulnerabilities
- CVE-2023-27532 disclosed in Veeam Backup & Replication — unauthenticated credential extraction via TCP 9401, later exploited by FIN7 and Cuba ransomware
- Cuba ransomware group observed actively exploiting CVE-2023-27532 against US critical infrastructure organizations
- CVE-2024-40711 disclosed — pre-authentication RCE in Veeam, subsequently exploited by Akira ransomware operators
- BleepingComputer, The Hacker News, Arctic Wolf, SOCRadar, and CSO Online publish advisories warning of critical Veeam RCE flaws
- NVD publishes CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708, CVE-2026-21668, CVE-2026-21670, CVE-2026-21671, CVE-2026-21672
- Veeam releases patched builds 12.3.2.4465 (v12) and 13.0.1.2067 (v13) to address all 8 vulnerabilities
- Veeam publishes security advisories KB4830 (v12) and KB4831 (v13) disclosing 8 vulnerabilities including 4 critical CVSS 9.9 RCEs
- Penligent and runZero publish deep technical analysis of the Veeam vulnerability cluster and asset discovery guidance
- No public PoC exploits or confirmed active exploitation as of this date; EPSS probability remains low at 0.00366
- As of 2026-05-29, all 8 Veeam Backup & Replication CVEs (incl. CVE-2026-21666, CVSS 9.9) remain fixed in builds 12.3.2.4465/13.0.1.2067, with no public PoC, no confirmed in-the-wild exploitation, and no CISA KEV listing per NVD, SOCRadar, Greenbone and Hacker News. PATCHED status holds; monitoring is warranted given Veeam's history of rapid ransomware weaponization.
Sources cited for Veeam Backup & Replication 8 Critical Vulnerabilities
- Veeam Security Bulletin KB4830 — Vulnerabilities Resolved in v12.3.2.4465
- Veeam Security Bulletin KB4831 — Vulnerabilities Resolved in v13.0.1.2067
- NVD — CVE-2026-21666
- Veeam Patches 7 Critical Backup & Replication Flaws — The Hacker News
- Veeam warns of critical flaws exposing backup servers to RCE attacks — BleepingComputer
- SOCRadar — Veeam Backup & Replication CVE-2026-21666 and Related RCE Fixes
- Arctic Wolf — Multiple Authenticated Vulnerabilities in Veeam Backup & Replication
- Veeam CVE — Why Backup Infrastructure Has Become Dangerous — Penligent
- CSO Online — Veeam warns admins to patch now as critical RCE flaws hit Backup & Replication
- Veeam Patches Multiple Critical RCE Vulnerabilities — CyberSecurity News
- Veeam patches critical RCE vulnerabilities — SC Media
- runZero — Veeam RCE vulnerabilities: How to find impacted assets
- Cuba ransomware uses Veeam exploit against critical U.S. organizations — BleepingComputer (Historical)
- Veeam KB3103 — List of Security Fixes and Improvements
Threats related to Veeam Backup & Replication 8 Critical Vulnerabilities
Detection coverage for TL-2026-0232
As of 2026-03-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0232 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.