Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Sandboxing Closes the Phishing Detection Visibility Gap
September 23, 2026
Critical cPanel Vulnerability Exposes User Accounts
September 23, 2026
Outerlimit Raises $16M to Secure AI Agents with Zero Trust
September 23, 2026
Home/Vulnerabilities/Critical Veeam Agent for Windows Flaw (CVE-2023-27532) Actively Exploited
Vulnerabilities

Critical Veeam Agent for Windows Flaw (CVE-2023-27532) Actively Exploited

Key Takeaways A critical local privilege escalation vulnerability (CVE-2026-32996) in Veeam Agent for Microsoft Windows is being actively exploited. The flaw allows a low-privileged local user to...

Emy Elsamnoudy
Emy Elsamnoudy
September 22, 2026 3 Min Read
12 0

Key Takeaways

  • A critical local privilege escalation vulnerability (CVE-2026-32996) in Veeam Agent for Microsoft Windows is being actively exploited.
  • The flaw allows a low-privileged local user to execute commands with NT AUTHORITYSYSTEM privileges.
  • All versions of Veeam Agent for Microsoft Windows 13.0.1.2067 and earlier 13 builds are vulnerable.
  • Veeam has released a patch in Veeam Agent for Microsoft Windows build 13.0.3.1220.

Critical Veeam Agent for Windows Flaw Under Active Exploitation

A severe local privilege escalation vulnerability impacting Veeam Agent for Microsoft Windows, identified as CVE-2026-32996, has become a significant concern for cybersecurity professionals. The disclosure of public proof-of-concept (PoC) exploit code has elevated the risk, confirming active exploitation of the flaw.

Table Of Content

  • Key Takeaways
  • Critical Veeam Agent for Windows Flaw Under Active Exploitation
  • Technical Details of CVE-2026-32996
  • Impact and Remediation
  • What You Should Do

This vulnerability enables an attacker with limited local access to execute arbitrary commands with the highest possible privileges on a Windows system, specifically NT AUTHORITYSYSTEM. The public release of technical details and exploit code on September 14, 2026, significantly increases the likelihood of threat actors incorporating this issue into their post-compromise attack chains.

Technical Details of CVE-2026-32996

The vulnerability resides within the Veeam Endpoint Backup service, which manages privileged client operations via a local gRPC named pipe located at \.pipeVeeamVAWServiceConnectionPipe. The affected software includes Veeam Agent for Microsoft Windows version 13.0.1.2067 and all preceding 13 builds.

Security researcher GitHub researcher suce0155 found that the service incorrectly associates an elevated administrator identity with a client-controlled session UID. Crucially, this UID is not securely bound to the initiating user or the original pipe connection. This design flaw permits a local attacker to reuse an already elevated session identifier, thereby tricking the Veeam service into executing commands with SYSTEM-level permissions.

The necessary session identifiers can be retrieved from the Svc.VeeamEndpointBackup.log file, typically found at C:ProgramDataVeeamEndpoint. Since standard local users possess read access to this log file, an attacker with even minimal access can search for a valid UID and then supply it to the exposed service interface to achieve privilege escalation.

Publicly available exploit code demonstrates this vulnerability by locating a valid Global Unique Identifier (GUID) within the Veeam log file and then executing the Windows whoami command. The output of this command, written to a file, confirms that the process runs under the NT AUTHORITYSYSTEM account, validating the successful privilege escalation.

Impact and Remediation

While exploiting this vulnerability requires local access, attackers frequently gain initial low-level access through various common vectors such as phishing campaigns, stolen credentials, malware infections, or compromised remote-access accounts. Obtaining SYSTEM privileges represents the highest level of control on most Windows systems, granting an attacker extensive capabilities.

A successful attacker could leverage this elevated access to disable security software, access sensitive data, alter critical system configurations, establish persistent footholds, steal additional credentials, or move laterally across an enterprise network, escalating the severity of an initial compromise.

Veeam has released a fix for this vulnerability in Veeam Agent for Microsoft Windows build 13.0.3.1220. Organizations are advised to upgrade Veeam Backup & Replication to version 13.0.2.29 or later, which includes the updated Windows agent with the critical patch.

What You Should Do

  • Immediately identify and update all installations of Veeam Agent for Microsoft Windows version 13.0.1.2067 and older 13 builds to Veeam Agent for Microsoft Windows build 13.0.3.1220.
  • If using Veeam Backup & Replication, upgrade to version 13.0.2.29 or newer to ensure the Windows agent is updated to the patched build.
  • Prioritize patching on shared workstations, servers, administrator endpoints, and devices utilized by backup operators or help desk personnel, as these systems pose a higher risk due to increased likelihood of local access.
  • As there is no reliable vendor-supported workaround for CVE-2026-32996, patching remains the primary mitigation.
  • Until patching is complete, limit interactive access to affected endpoints, rigorously review local account permissions, restrict backup operator and administrator rights, and implement enhanced monitoring for suspicious activity related to the Veeam Endpoint Backup service, its log files, and any unexpected child processes launched with SYSTEM privileges.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchphishingSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

BambooToken Linux Backdoor Uses MQTT for Remote Shell and File Exfiltration

Next Post

Critical Red Hat OpenShift Flaw (CVE-2024-XXXX) Lets Attackers Bypass PGP Checks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical AWS Lambda Flaw Bypasses IAM, Exposes Cloud Services
September 23, 2026
Critical Next.js CVE-2024-XXXXX RCE Flaw Lets Attackers Use SVG Files
September 23, 2026
New Malware Uses Evasive Domain Tactics to Hide Infrastructure
September 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us