Veeam Agent CVE-2026-32996: public PoC and patch dispute
CVE-2026-32996 lets a local user reach SYSTEM on Veeam Agent for Windows through 13.0.1.2067; the patch is agent 13.0.3.1220, and sources disagree on in-the-wild use.
CVE-2026-32996 is a local privilege-escalation flaw in Veeam Agent for Microsoft Windows affecting 13 builds through 13.0.1.2067, allowing a low-privileged local user to gain NT AUTHORITY\SYSTEM. Security Affairs, GBHackers, and Cyber Security News say public technical details and a proof-of-concept were released on September 14, 2026, with GBHackers and Cyber Security News naming researcher suce0155; GBHackers adds that the issue is not remotely exploitable without an existing local foothold. Those reports say Veeam fixed it in agent build 13.0.3.1220, shipped with Veeam Backup & Replication 13.0.2.29 or later, and that no official workaround exists. The Canadian Centre for Cyber Security updated advisory AV26-513 on September 21, 2026, covering fixes first published May 27 for Backup & Replication 13 before 13.0.2.29, Veeam ONE before 13.0.2.6723, and Veeam Service Provider Console 9.2 before 9.2.1.33875, and said open-source reporting indicates CVE-2026-32996 is being exploited in the wild. Headlines from GBHackers and Cyber Security News also describe active exploitation, but their article bodies, like Security Affairs, describe a public proof-of-concept rather than confirmed in-the-wild incidents.
- CVE-2026-32996 is a local privilege escalation to NT AUTHORITY\SYSTEM in Veeam Agent for Microsoft Windows 13 builds through 13.0.1.2067.
- Security Affairs, GBHackers, and Cyber Security News report a public proof-of-concept and technical details released on September 14, 2026; GBHackers and Cyber Security News attribute it to researcher suce0155.
- GBHackers says the flaw is not remotely exploitable on its own and needs an existing local foothold.
- The fix is agent build 13.0.3.1220, delivered by Veeam Backup & Replication 13.0.2.29 or later; those reports say no official workaround exists.
- Canadian Centre for Cyber Security advisory AV26-513, covering May 27, 2026 Veeam fixes, was updated September 21, 2026, and cites open-source reporting that CVE-2026-32996 is exploited in the wild.
- AV26-513 lists Backup & Replication 13 before 13.0.2.29, Veeam ONE before 13.0.2.6723, and Veeam Service Provider Console 9.2 before 9.2.1.33875.
- GBHackers and Cyber Security News headlines say the flaw is exploited, but their bodies, like Security Affairs, describe a public proof-of-concept rather than confirmed incidents.
Coverage timelineoldest first · each row is one article
- · 5d agoVeeam security advisory (AV26-513) – Update 1
Canadian Centre for Cyber Security· 76
Canada's Cyber Centre warns CVE-2026-32996 is being exploited and urges Veeam updates.
- · 4d agoPublic PoC Exposes Critical Veeam Agent Privilege Escalation
Security Affairs· 58
Public PoC for CVE-2026-32996 lets low-privileged local users gain SYSTEM on Veeam Agent for Windows; patch to 13.0.2.29 or later.
- · 4d ago
Vulnerabilities in this storyAll →
- CVE-2026-329967.3<1%This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalationpublished PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-32996 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation |