


Perceptive Security
SOC/SIEM Consultancy

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Published:
11 March 2026 at 23:00:00
Alert date:
12 March 2026 at 16:03:23
Source:
nvd.nist.gov
Enterprise Applications, Data Breach & Exfiltration
CVE-2026-21666 is a vulnerability that allows authenticated domain users to perform remote code execution (RCE) on Veeam Backup Server systems. The vulnerability affects backup infrastructure and poses a high risk as it enables code execution with authenticated access. This could allow attackers to compromise backup systems and potentially access or manipulate backup data. The vulnerability has been assigned a high criticality rating and affects enterprise backup solutions.
Technical details
Mitigation steps:
Affected products:
Veeam Backup Server
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
