TL;DR
A critical Veeam Agent vulnerability is under active attack on Windows networks. The details of the vulnerability and the proof-of-concept exploit code have been publicly disclosed. System administrators must apply the latest vendor updates immediately to prevent complete endpoint takeover.
- CVE: CVE-2026-32996
- CVSS: 7.3 (High · CVSSv4)
- Product: Veeam Backup and Replication
- Affected: 13
- Status: Exploited in the wild
- EPSS: 0.2% (30-day)
- Action: See vendor advisory
Track every Veeam CVE the moment it's exploited.
Get free email alertsWhy It Matters
This actively exploited Veeam Agent vulnerability poses a significant risk to shared workstations and servers. A low-privileged user with local access can elevate their permissions to NT AUTHORITY\SYSTEM. Cybersecurity researchers from Arctic Wolf confirmed that threat actors are currently exploiting the flaw in the wild. Furthermore, the details of the vulnerability and the proof-of-concept exploit code have been publicly disclosed. The public availability of the PoC script drastically lowers the barrier to entry for attackers. Consequently, any compromised low-level account can facilitate a full system compromise.
How The Attack Works
The issue originates in the Veeam Endpoint Backup service. Specifically, the flaw “stems from the Veeam Endpoint Backup service’s handling of elevated client sessions over the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe.” During this process, “the service caches an elevated administrator principal against a client-controlled session UID that is not bound to the requesting user or connection.” The vulnerability triggers because these sensitive identifiers are stored insecurely. The threat summary notes that “because elevated session UIDs are written to C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log, which standard users can read, an attacker can obtain a valid UID and abuse it to execute commands as SYSTEM.” The public GitHub PoC demonstrates this exploit by running basic commands and writing the output to a file.
Affected Versions
The flaw affects Veeam Agent for Microsoft Windows version 13.0.1.2067. It also impacts all earlier version 13 builds.
Patch Or Mitigation Steps
Administrators must upgrade their deployments to Veeam Backup & Replication version 13.0.2.29 or later. This release updates the agent to the secure build 13.0.3.1220. The official Veeam security advisory contains specific download instructions. Security analysts recommend prioritizing remediation on shared servers and administrator workstations. If immediate patching is impossible, security teams should limit interactive local access to affected endpoints. Restrict local administrator and backup operator privileges to required personnel only.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!