Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilityendpoint-software-vulnerability

Veeam Patches Critical RCE and Privilege Escalation Flaws Across Backup Products

Updated 28d agoFirst seen May 25, 20265 sources

Veeam released security updates for multiple products after disclosing several vulnerabilities that affect enterprise backup and monitoring environments, including Veeam Backup & Replication, Veeam ONE, and Veeam Service Provider Console. The most severe issue, CVE-2026-32998, is a critical remote code execution flaw in Veeam Service Provider Console with a CVSS score of 9.4; Veeam said it is fixed in version 9.2.1.33875. Canadian Centre for Cyber Security advisory AV26-513 said affected versions include Veeam Backup & Replication 13 releases before 13.0.2.29, Veeam ONE releases before 13.0.2.6723, and Veeam Service Provider Console 9.2 releases before 9.2.1.33875, and urged administrators to apply the vendor updates.

Veeam also patched CVE-2026-32996, a high-severity local privilege escalation flaw in Veeam Agent for Microsoft Windows that could let a low-privileged local user gain administrative control, and CVE-2026-32997, an arbitrary file write issue affecting Linux-based backup servers running the Veeam Software Appliance that could allow an authenticated backup administrator to modify system files. For organizations unable to patch immediately, Veeam provided a workaround for the Service Provider Console bug by disabling the AlarmManagement_ScriptExecution setting in the local configuration JSON file, while older reporting on Veeam ONE underscores the continued security focus on Veeam’s management stack.

Share:
Veeam Patches Critical RCE and Privilege Escalation Flaws Across Backup Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 27, 202630d ago

Veeam patches CVE-2026-32997 affecting Linux-based backup servers

Veeam fixed CVE-2026-32997, an arbitrary file write vulnerability affecting Linux-based backup servers running the Veeam Software Appliance. The issue could allow an authenticated backup administrator to modify system files.

Veeam Security Vulnerabilities: Critical Patches Released

Veeam patches CVE-2026-32996 in Veeam Agent for Microsoft Windows

Veeam addressed CVE-2026-32996, a high-severity local privilege escalation vulnerability in Veeam Agent for Microsoft Windows. According to the report, the flaw could allow a low-privileged local attacker to gain administrative control and was reported by researcher "Alibabas."

Veeam Security Vulnerabilities: Critical Patches Released

Veeam fixes critical CVE-2026-32998 in Service Provider Console

Veeam released a fix for CVE-2026-32998, a critical remote code execution vulnerability in Veeam Service Provider Console with a CVSS score of 9.4. The flaw was discovered by researcher "putsi" through HackerOne, and Veeam said it is fixed in version 9.2.1.33875 while also providing a workaround to disable AlarmManagement_ScriptExecution in the local configuration JSON file.

Veeam Security Vulnerabilities: Critical Patches Released

Veeam publishes security advisories and patches multiple product flaws

On 2026-05-27, Veeam published security advisories addressing vulnerabilities in multiple products, including Veeam Backup & Replication, Veeam ONE, and Veeam Service Provider Console. The advisories covered affected versions prior to Backup & Replication 13.0.2.29, Veeam ONE 13.0.2.6723, and Service Provider Console 9.2.1.33875.

Veeam security advisory (AV26-513) - Canadian Centre for Cyber Security
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
2 linked
Veeam Backup & ReplicationVeeam Service Provider Console
Organizations
3 linked
Veeam SoftwareAlibaba CloudHackerOne
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.