CVE-2026-21667: Critical severity Veeam Veeam Backup \& Replication vulnerability
Published Mar 12, 2026
·Updated
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Affected Software
1 affected component
Veeam Veeam Backup \& Replication>=12.0.0.1402<12.3.2.4465
Event History
Mar 12, 2026
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
News Published
via BleepingComputer·04:59 PM
News Published
via BleepingComputer·05:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-21667?
CVE-2026-21667 is considered critical due to its potential for remote code execution by authenticated domain users.
2
How does CVE-2026-21667 allow for remote code execution?
CVE-2026-21667 allows authenticated domain users to exploit vulnerabilities in Veeam Backup & Replication software to execute arbitrary code.
3
Which versions of Veeam Backup & Replication are affected by CVE-2026-21667?
CVE-2026-21667 affects Veeam Backup & Replication versions between 12.0.0.1402 and 12.3.2.4465.
4
How can I fix CVE-2026-21667?
To remediate CVE-2026-21667, users should update their Veeam Backup & Replication software to the latest patched version.
5
What are the risks associated with CVE-2026-21667?
The risks of CVE-2026-21667 include unauthorized access and control over backup servers, potentially leading to data loss and breaches.