PT-2026-24952 · Veeam+1 · Backup/Replication+1

Published

2026-03-12

·

Updated

2026-03-15

·

CVE-2026-21666

CVSS v3.1
9.9
VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
🚨 CVE-2026-21666 (CVSS 9.9) – Critical Veeam Backup RCE Could Let Attackers Take Over Backup Servers https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/:
  1. New PhantomRaven NPM attack wave steals dev data via 88 packages Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys ShinyHunters claims ongoing Salesforce Aura data theft attacks England Hockey investigating ransomware data breach AI-generated Slopoly malware used in Interlock ransomware attack Don’t miss a 2-in-1 open-box Chromebook with stylus for just $150 Veeam warns of critical flaws exposing backup servers to RCE attacks How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry Ho...
@secharvester

Fix

RCE

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2026-03174
CVE-2026-21666

Affected Products

Backup/Replication
Veeam Backup & Replication