What it is
CVE-2026-32996 is a vulnerability affecting Veeam Backup and Replication. This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
Vulnerability report
Backup and Replication Privilege Escalation
Veeam / Backup and Replication · 13 to <= 13.0.1
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-32996 is a vulnerability affecting Veeam Backup and Replication. This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is high. Also confirmed by third-party sources.
Who is affected?
Veeam / Backup and Replication 13 to <= 13.0.1.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Arctic Wolf
A trusted third party reported exploitation.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Arctic Wolf First | 2026-09-21 20:34 UTC |
| The Hacker News | 2026-09-22 06:32 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.2%
Recent mention · Security Affairs
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not...
Read full advisoryRecent mention · Security Affairs
Public PoC Exposes Critical Veeam Agent Privilege EscalationSecurity Affairs · 22 Sep 2026
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details […]
Recent mention · The Hacker News
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessThe Hacker News · 22 Sep 2026
Ravie LakshmananSep 22, 2026Vulnerability / Endpoint Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution. "A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware...
Recent mention · Arctic Wolf
UPDATE: Active Exploitation CVE-2026-32996 of Veeam AgentArctic Wolf · 16 Sep 2026
Threat Summary On September 14, 2026, public technical details and proof-of-concept (PoC) exploit code were released for CVE-2026-32996, increasing the likelihood of exploitation attempts against affected Veeam Agent for Microsoft Windows deployments. CVE-2026-32996 is a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows version 13.0.1.2067 and affects all earlier version 13 builds. Exploitation ... UPDATE: Active Exploitation CVE-2026-32996 of Veeam Agent
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-09-15 18:28:22 UTC · 0 stars · AI assessment 85%
A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
Timeline
06:32 UTC
Exploitation attested by an external source
20:34 UTC
High-confidence, third-party attested exploitation
18:28 UTC
Public proof-of-concept code published
04:01 UTC
Vulnerability disclosed publicly
15:00 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-32996
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-32996",
"confidence": "High",
"cvss_score": 7.3,
"cvss_estimated": false,
"epss_score": 0.00157,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}