Veeam released security updates for multiple products after disclosing several vulnerabilities that affect enterprise backup and monitoring environments, including Veeam Backup & Replication, Veeam ONE, and Veeam Service Provider Console. The most severe issue, CVE-2026-32998, is a critical remote code execution flaw in Veeam Service Provider Console with a CVSS score of 9.4; Veeam said it is fixed in version 9.2.1.33875. Canadian Centre for Cyber Security advisory AV26-513 said affected versions include Veeam Backup & Replication 13 releases before 13.0.2.29, Veeam ONE releases before 13.0.2.6723, and Veeam Service Provider Console 9.2 releases before 9.2.1.33875, and urged administrators to apply the vendor updates.
Veeam also patched CVE-2026-32996, a high-severity local privilege escalation flaw in Veeam Agent for Microsoft Windows that could let a low-privileged local user gain administrative control, and CVE-2026-32997, an arbitrary file write issue affecting Linux-based backup servers running the Veeam Software Appliance that could allow an authenticated backup administrator to modify system files. For organizations unable to patch immediately, Veeam provided a workaround for the Service Provider Console bug by disabling the AlarmManagement_ScriptExecution setting in the local configuration JSON file, while older reporting on Veeam ONE underscores the continued security focus on Veeam’s management stack.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Veeam fixed CVE-2026-32997, an arbitrary file write vulnerability affecting Linux-based backup servers running the Veeam Software Appliance. The issue could allow an authenticated backup administrator to modify system files.
Veeam addressed CVE-2026-32996, a high-severity local privilege escalation vulnerability in Veeam Agent for Microsoft Windows. According to the report, the flaw could allow a low-privileged local attacker to gain administrative control and was reported by researcher "Alibabas."
Veeam released a fix for CVE-2026-32998, a critical remote code execution vulnerability in Veeam Service Provider Console with a CVSS score of 9.4. The flaw was discovered by researcher "putsi" through HackerOne, and Veeam said it is fixed in version 9.2.1.33875 while also providing a workaround to disable AlarmManagement_ScriptExecution in the local configuration JSON file.
On 2026-05-27, Veeam published security advisories addressing vulnerabilities in multiple products, including Veeam Backup & Replication, Veeam ONE, and Veeam Service Provider Console. The advisories covered affected versions prior to Backup & Replication 13.0.2.29, Veeam ONE 13.0.2.6723, and Service Provider Console 9.2.1.33875.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecyber.gc.ca
Open sourceveeam.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.