# Multiple vulnerabilities in Veeam Backup & Replication before 13.0.2.29 allow privilege…

Published: 2026-05-27 · Severity: high
Canonical: https://vorant.io/reports/c4bf4f84-ca7c-48b8-8071-b04b2dfe75a2/multiple-vulnerabilities-in-veeam-backup-replication-before-13-0-2-29-allow

> Multiple vulnerabilities in Veeam Backup & Replication before 13.0.2.29 allow privilege escalation and data integrity compromise.

The French CERT (CERT-FR) has issued an advisory regarding multiple security vulnerabilities discovered in Veeam Backup & Replication versions prior to 13.0.2.29. These flaws enable attackers to achieve privilege escalation and compromise data integrity within affected backup infrastructure environments.

Veeam has released version 13.0.2.29 to address these issues, tracked as CVE-2026-32996 and CVE-2026-32997. Organizations using Veeam Backup & Replication should prioritize applying the vendor's patches, as backup infrastructure represents a critical attack surface — compromise of backup systems can facilitate ransomware attacks by allowing threat actors to delete or encrypt backup data, eliminating recovery options.

Given the strategic importance of backup solutions in enterprise environments and the potential for privilege escalation to enable broader network compromise, administrators should treat this as a priority patching event and verify the integrity of their backup infrastructure following remediation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-32996, CVE-2026-32997

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0652

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c4bf4f84-ca7c-48b8-8071-b04b2dfe75a2/multiple-vulnerabilities-in-veeam-backup-replication-before-13-0-2-29-allow.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
