VYPR
Critical severity9.1NVD Advisory· Published Mar 12, 2026· Updated May 10, 2026

CVE-2026-21671

CVE-2026-21671

Description

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

Affected products

2
  • cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*
    Range: >=13.0.0.496,<=13.0.1.1071
  • Veeam/Software Appliancev5
    Range: 13.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.