Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-32996 Under Active Exploitation: What Defenders Should Do Now

CVE-2026-32996 Under Active Exploitation: What Defenders Should Do Now Overview CVE-2026-32996 is a high-severity local privilege escalation in Veeam Agent for Microsoft Windows, rated 7.3 under CVSS v4. Researchers report active exploitation in the wild, and public proof-of-concept code has been disclosed, sharply lowering the effort required to attack unpatched endpoints. Mechanism and…

A critical vulnerability, CVE-2026-32996, is actively being exploited in Veeam Agent for Microsoft Windows. This local privilege escalation flaw allows attackers to gain system-level access, opening the door to defense evasion, persistence, credential theft, and lateral movement within a network.

The vulnerability arises from the Veeam Endpoint Backup service's handling of elevated administrator sessions over a local gRPC named pipe. The service caches an administrator principal, which can be stolen by another local process. This stolen session UID is then written to a readable log file, enabling attackers to replay the UID and execute commands as SYSTEM.

Public proof-of-concept code has been released, making the attack easier to carry out. Successful exploitation could allow attackers to access backup repositories and recovery data stored in the backup agent.

Vulnerable versions include all builds of Veeam Agent for Microsoft Windows 13.0.1.2067 and earlier. The vendor has released a patch in Veeam Backup & Replication 13.0.2.29 or later. Until the patch can be applied, users should limit local access, restrict privileges, and monitor for unusual SYSTEM-level activity. Prioritize protecting shared servers and administrator workstations.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Touch ’n Go To Add 10 Enhanced RFID Lanes Across Five Highways By Year-End

Touch ’n Go is expanding its Enhanced Radio Frequency Identification (Enhanced RFID) network with 10 additional lanes across five highways by the end of this year. The expansion is part of the company’s efforts to support Malaysia’s transition towards a Multi-Lane Free Flow (MLFF) tolling system, which is designed to allow vehicles to…

More from Wednesday 30 September →