CVE-2026-21666: Critical severity Veeam Veeam Backup \& Replication vulnerability
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21666?
CVE-2026-21666 is classified as a critical vulnerability due to its potential for remote code execution by authenticated domain users.
How do I fix CVE-2026-21666?
To mitigate CVE-2026-21666, upgrade your Veeam Backup & Replication to the latest version that addresses the vulnerability.
Who is affected by CVE-2026-21666?
CVE-2026-21666 affects authenticated domain users with access to Veeam Backup & Replication versions between 12.0.0.1402 and 12.3.2.4465.
What are the potential impacts of CVE-2026-21666?
Exploitation of CVE-2026-21666 could allow an attacker to execute arbitrary code on the Backup Server, compromising data integrity and confidentiality.
Is a patch available for CVE-2026-21666?
Yes, a security patch is available to resolve CVE-2026-21666 in the latest updates of Veeam Backup & Replication.