Search
Find merged stories by title or summary.
Veeam Agent Flaw Actively Exploited to Gain SYSTEM Privileges on Windows
A critical local privilege escalation flaw in Veeam Agent for Microsoft Windows is drawing attention after public proof-of-concept exploit code became available. The vulnerability, tracked as CVE-2026-32996 , could let a low-privileged local user run commands with NT AUTHORITY\SYSTEM permissions on affected Windows devices. Technical details and exploit code were publicly released on September 14, 2026, increasing the risk that threat actors may incorporate the issue into post-compromise attack chains. The flaw affects Veeam Agent for Microsoft Windows version 13. 0. 1. 2067 and earlier 13 builds. The issue exists in the Veeam Endpoint Backup service, which handles privileged client activity through a local gRPC named pipe located at \\.\pipe\Veeam\VAW\ServiceConnectionPipe.
Hackers Exploit Veeam Agent Flaw to Gain SYSTEM Privileges on Windows
A newly disclosed active exploitation of a critical local privilege escalation flaw in Veeam Agent for Microsoft Windows that enables attackers to elevate low-privileged access to NT AUTHORITY\SYSTEM on vulnerable endpoints. Tracked as CVE-2026-32996 , the vulnerability affects Veeam Agent for Microsoft Windows version 13. 0. 1. 2067 and earlier Version 13 builds. Public technical analysis and proof-of-concept exploit code became available on September 14, significantly increasing the risk that threat actors and post-exploitation operators will adopt the flaw in real-world intrusion chains. Hackers Exploit Veeam Agent Flaw The vulnerability exists in the Veeam Endpoint Backup service, which manages elevated client sessions over the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe .
Public PoC Exposes Critical Veeam Agent Privilege Escalation
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details and a proof-of-concept exploit dropped for CVE-2026-32996. From that point on, the odds of active exploitation went up considerably, because once working code sits on GitHub, anyone can copy it and adapt it in an afternoon. Arctic Wolf already flagged this in a bulletin. “On September 14, 2026, public technical details and proof-of-concept (PoC) exploit code were released for CVE-2026-32996, increasing the likelihood of exploitation attempts against affected Veeam Agent for Microsoft Windows deployments.” warns Arctic Wolf.
[Previdian] CVE-2026-32996 - Confirmed Exploitation
CVE-2026-32996 Catalog: Previdian Status: Confirmed Exploited: Yes Status Updated: 2026-09-21 20:34 UTC Evidence Sources: 1 First Seen: 2026-09-21 Asserted: 2026-09-21
You've reached the end of current stories for this search.
