Public proof-of-concept exploit code and technical details are available for CVE-2026-32996, a local privilege-escalation flaw in Veeam Agent for Microsoft Windows. A locally authenticated low-privileged user can abuse insecure handling of elevated session identifiers through the Veeam Endpoint Backup service’s local gRPC named pipe to execute commands as NT AUTHORITY\SYSTEM; reporting indicates active exploitation.
The issue affects version 13 builds through Veeam Agent 13.0.1.2067. Organizations should upgrade Veeam Backup & Replication to 13.0.2.29 or later, which deploys the fixed Windows agent build 13.0.3.1220. No official workaround is available, so remediation should be prioritized for shared systems and endpoints accessible to privileged or interactive users; where patching is delayed, local interactive access should be restricted.

See which actors are running it and whether you're in range.
1 event from the most recent confirmed update back to the earliest known activity.
Public technical details and GitHub proof-of-concept exploit code were released for CVE-2026-32996, a local privilege-escalation flaw in Veeam Agent for Microsoft Windows. The PoC abuses exposed elevated session UIDs to allow a low-privileged local user to execute commands as NT AUTHORITY\SYSTEM on affected version 13 installations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcearcticwolf.com
Open sourcearcticwolf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.