Veeam security advisory (AV26-513) – Update 1
Canada's Cyber Centre warns CVE-2026-32996 is being exploited and urges Veeam updates.
The Canadian Centre for Cyber Security updated advisory AV26-513 on September 21, 2026, covering Veeam fixes first published on May 27. The updates address Veeam Backup & Replication 13 before 13.0.2.29, Veeam ONE before 13.0.2.6723, and Veeam Service Provider Console 9.2 before 9.2.1.33875. Update 1 says open-source reporting indicates CVE-2026-32996 is being exploited in the wild. The centre urges users and administrators to review Veeam's notices and apply the updates.
- Advisory AV26-513 was updated on September 21 after May 27 Veeam fixes.
- Backup & Replication before 13.0.2.29, ONE before 13.0.2.6723, and Console before 9.2.1.33875 are affected.
- Open-source reporting says CVE-2026-32996 is exploited in the wild.
- The Cyber Centre urges administrators to apply the vendor updates.
Vulnerabilities mentionedAll →
- CVE-2026-329967.3<1%This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalationpublished PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-32996 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation |
Full article123 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-513
Date: May 27, 2026
Updated: September 21, 2026
On May 27, 2026, Veeam published security advisories to address vulnerabilities in the following products:
- Veeam Backup & Replication – 13 versions prior to 13.0.2.29
- Veeam ONE – versions prior to 13.0.2.6723
- Veeam Service Provider Console – 9.2 versions prior to 9.2.1.33875
Update 1
Open-source reporting indicates that CVE-2026-32996 is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/veeam-security-advisory-av26-513