Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Veeam Agent Vulnerability Exploited for SYSTEM Privileges

Veeam Agent Vulnerability Exploited for SYSTEM Privileges

Posted on September 22, 2026 By CWS

A critical vulnerability in Veeam Agent for Microsoft Windows is under scrutiny following the release of a public proof-of-concept exploit. The flaw allows low-privileged local users to execute commands with elevated NT AUTHORITYSYSTEM permissions on susceptible Windows machines.

Details of the Veeam Agent Vulnerability

The vulnerability, identified as CVE-2026-32996, surfaced after technical details and exploit code were made public on September 14, 2026. This disclosure raises the possibility of its exploitation in post-compromise strategies by cyber attackers. The affected versions include Veeam Agent for Microsoft Windows version 13.0.1.2067 and earlier builds.

The issue stems from the Veeam Endpoint Backup service, which facilitates privileged actions via a local gRPC named pipe. This service inadvertently stores an elevated administrator identity linked to a session UID that is not securely associated with the user or the original pipe connection.

Exploitation Mechanism and Risks

A GitHub researcher, known by the handle suce0155, discovered that attackers could exploit this flaw by reusing an elevated session identifier. This would enable the execution of commands with SYSTEM-level rights. The session identifiers can be extracted from the Svc.VeeamEndpointBackup.log file located in C:ProgramDataVeeamEndpoint.

Standard local users, who can access this log file, may locate a valid UID and leverage it to interact with the exposed service interface. Publicly available exploit scripts demonstrate how to locate a GUID within the log file and execute the Windows ‘whoami’ command, verifying SYSTEM-level execution.

Mitigation and Recommendations

Although exploiting this flaw requires local access, attackers frequently gain such access via phishing, stolen credentials, or malware. Once SYSTEM privileges are obtained, attackers can disable security tools, access sensitive data, alter system configurations, and move laterally across networks.

Veeam has resolved this issue in the Veeam Agent for Microsoft Windows build 13.0.3.1220. Organizations are urged to upgrade to Veeam Backup & Replication version 13.0.2.29 or newer, which includes the patched Windows agent.

Security teams should promptly identify and update systems running vulnerable versions, prioritizing shared workstations, servers, and devices used by administrators and backup operators. No vendor-supported workaround is available, making an upgrade essential.

Until updates are applied, minimizing exposure is crucial. This includes restricting interactive access to affected systems, reviewing local account permissions, limiting backup operator and administrator rights, and monitoring for unusual activity related to the Veeam Endpoint Backup service.

Cyber Security News Tags:CVE-2026-32996, Cybersecurity, exploit code, local privilege escalation, patch update, security flaw, system privileges, Veeam Agent, vulnerability management, Windows security

Post navigation

Previous Post: Critical AI Gateway Flaw Exposes Bifrost to Command Attacks

Related Posts

SideWinder Targets Government Emails with Fake PDF Viewer SideWinder Targets Government Emails with Fake PDF Viewer Cyber Security News
INE Security Expands Across Middle East and Asia to Accelerate Cybersecurity Upskillin INE Security Expands Across Middle East and Asia to Accelerate Cybersecurity Upskillin Cyber Security News
Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges Windows Heap-based Buffer Overflow Vulnerability Let Attackers Elevate Privileges Cyber Security News
PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access Cyber Security News
FileFix Attack Exploits Windows Browser Features to Bypass Mark-of-the-Web Protection FileFix Attack Exploits Windows Browser Features to Bypass Mark-of-the-Web Protection Cyber Security News
American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign American Airlines Subsidiary Envoy Compromised in Oracle Hacking Campaign Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion
  • Malicious npm Package Targets Twilio Developers
  • Enhancing SOC Efficiency with Threat Intelligence

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark