Veeam Patches Multiple Critical RCE Vulnerabilities on Backup Server
## Security Update for Veeam Backup & Replication Software
Security Update for Veeam Backup & Replication Software
On Thu, Mar 12, 2026, Veeam released a crucial security patch (Build 12.3.2.4465) for its Backup & Replication software. This update addresses severe vulnerabilities that could permit unauthorized remote code execution and privilege escalation by attackers.
The update resolves three critical-severity vulnerabilities with CVSS 3.1 scores of 9.9:
CVE-2026-21666: Enables an authenticated domain user to execute arbitrary remote code on the Veeam Backup Server. CVE-2026-21667: Similar to CVE-2026-21666, permitting remote code execution on the Backup Server. CVE-2026-21708: Allows an attacker with Backup Viewer permissions to perform remote code execution as the internal PostgreSQL user, compromising backend database processes.
Additionally, two high-severity vulnerabilities with CVSS scores of 8.8 were patched:
CVE-2026-21668: Allows an authenticated domain user to manipulate arbitrary files on a Backup Repository, affecting backup integrity. CVE-2026-21672: Enables local privilege escalation on Windows-based Veeam Backup & Replication servers.
On Thu, Mar 12, 2026, Veeam released a crucial security patch (Build 12.3.2.4465) for its Backup & Replication software.
The patch enhances system security by upgrading core components, including Decode-uri-component to version 0.2.2, Newtonsoft.Json to 13.0.3, and Path-to-RegExp to 1.9.0.
Operational issues have also been addressed. For systems updating RHEL infrastructure servers with the DISA STIG profile enabled, the public GPG key for Veeam packages will now update correctly. Administrators are advised to temporarily disable the fapolicyd service during the update process.
A deserialization error causing PostgreSQL item restores from Enterprise Manager to fail has been fixed.
Administrators are strongly encouraged to apply this security patch immediately. To verify your current version, access the Veeam Backup & Replication Console's Main Menu and navigate to Help, then About.
Organizations on version 12.3.2 (builds 12.3.2.3617 or 12.3.2.4165) can apply a smaller patch file, available as an ISO or an EXE. Deployments running older versions, such as 12.3.1 or earlier, must use the full installation ISO to upgrade to build 12.3.2.4465. Ensure downloaded files are unblocked before running the installer to avoid errors.
Based on reporting by Cyber Security News.
