PT-2026-24952 · Veeam+1 · Backup/Replication+1
Published
2026-03-12
·
Updated
2026-03-15
·
CVE-2026-21666
CVSS v3.1
9.9
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
🚨 CVE-2026-21666 (CVSS 9.9) – Critical Veeam Backup RCE Could Let Attackers Take Over Backup Servers
https://www.bleepingcomputer.com/news/security/veeam-warns-of-critical-flaws-exposing-backup-servers-to-rce-attacks/:
- New PhantomRaven NPM attack wave steals dev data via 88 packages Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys ShinyHunters claims ongoing Salesforce Aura data theft attacks England Hockey investigating ransomware data breach AI-generated Slopoly malware used in Interlock ransomware attack Don’t miss a 2-in-1 open-box Chromebook with stylus for just $150 Veeam warns of critical flaws exposing backup servers to RCE attacks How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry Ho...
@secharvester
Fix
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backup/Replication
Veeam Backup & Replication