CVE-2026-32996 in Veeam Agent Actively Exploited
A high-severity local privilege escalation in Veeam Agent for Microsoft Windows, rated 7.3 under CVSS v4, is under active exploitation with public proof-of-concept code available. Attackers can replay a cached session UID to gain SYSTEM privileges; the fix ships in Veeam Backup & Replication 13.0.2.29.
- CVE-2026-32996 is rated 7.3 under CVSS v4
- Exploitation grants NT AUTHORITY\SYSTEM on affected endpoints
- Patch: Veeam Backup & Replication 13.0.2.29, agent 13.0.3.1220
- Public PoC is disclosed and exploitation is active in the wild
Read next
Security