Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Veeam Fixes Critical Flaws in Backup Software

Veeam Fixes Critical Flaws in Backup Software

Posted on March 13, 2026 By CWS

Veeam has rolled out essential security patches to mitigate severe vulnerabilities in its Backup & Replication software. These vulnerabilities, if left unaddressed, could enable unauthorized remote code execution, posing a significant threat to user security.

Critical Vulnerabilities Identified

The identified vulnerabilities include CVE-2026-21666 and CVE-2026-21667, both carrying a high CVSS score of 9.9. These flaws permit authenticated domain users to execute remote code on the Backup Server. Another notable vulnerability, CVE-2026-21668, with a CVSS score of 8.8, allows bypassing restrictions to manipulate files on a Backup Repository. Additionally, CVE-2026-21672 and CVE-2026-21708 also highlight serious security concerns, such as local privilege escalation and remote code execution as the postgres user, respectively.

Software Versions Affected

These vulnerabilities impact Veeam Backup & Replication version 12.3.2.4165 and all prior versions. The company has addressed these issues in version 12.3.2.4465. Furthermore, the latest version 13.0.1.2067 resolves CVE-2026-21672 and CVE-2026-21708, alongside two additional critical vulnerabilities, CVE-2026-21669 and CVE-2026-21671.

Importance of Timely Updates

Veeam emphasizes the urgency of applying these updates, as attackers commonly attempt to reverse-engineer patches post-disclosure to exploit unpatched systems. With a history of Veeam software being targeted in ransomware attacks, updating to the latest version is crucial for user protection against emerging threats.

By staying informed and promptly applying security updates, users can significantly reduce their risk and ensure the integrity of their backup systems against potential exploitation.

The Hacker News Tags:backup security, CVE, Cybersecurity, enterprise security, IT security, ransomware protection, remote code execution, software updates, Veeam, vulnerability patch

Post navigation

Previous Post: Critical OpenSSH GSSAPI Flaw Threatens Linux Servers
Next Post: Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Related Posts

Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud The Hacker News
Wazuh for Regulatory Compliance Wazuh for Regulatory Compliance The Hacker News
AI’s Impact on Cybersecurity Response Times AI’s Impact on Cybersecurity Response Times The Hacker News
TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign The Hacker News
Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control The Hacker News
How to Advance from SOC Manager to CISO? How to Advance from SOC Manager to CISO? The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Splunk Enterprise Enables Unauthorized Code Execution
  • BugHunter Toolkit Enhances Vulnerability Detection
  • OceanLotus Targets Vietnamese Firms with SPECTRALVIPER
  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark