Veeam Agent for Windows LPE CVE-2026-32996 (CVSS 7.3); Arctic Wolf active exploitation after public PoC
Veeam KB4852 documents CVE-2026-32996, a local privilege escalation in Veeam Agent for Microsoft Windows: a low-privileged local user can obtain SYSTEM by abusing elevated session UIDs cached against a client-controlled session UID on the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe (UIDs readable from C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log). Vendor CVSS 4.0 score 7.3 High (AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). Affected: Agent builds through 13.0.1.2067 and earlier version-13 builds. Fixed starting with Veeam Backup & Replication 13.0.2.29 (Arctic Wolf: that upgrade also brings Agent build 13.0.3.1220). Arctic Wolf (16 September 2026) reports public PoC details released 14 September 2026 and warns of active exploitation attempts — prioritise shared workstations, admin endpoints, and multi-user hosts. Same KB also ships CVE-2026-32997 (Backup Administrator arbitrary file write on Linux Veeam Software Appliance; CVSS 4.0 8.6) fixed in the same 13.0.2.29 build. Primary: Veeam KB4852; exploitation context: Arctic Wolf; wire: The Hacker News 22 Sep 2026.
- Product
- Veeam Agent for Microsoft Windows (managed via Veeam Backup & Replication 13.x)
- Versions
- Affected: Veeam Agent for Microsoft Windows 13.0.1.2067 and earlier version-13 builds (per KB4852 / Arctic Wolf). Fixed: upgrade Veeam Backup & Replication to 13.0.2.29 or later (Agent fixed build 13.0.3.1220 per Arctic Wolf).
- CVSS
- (CVSS 4.0 High; Veeam)
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Upgrade Veeam Backup & Replication to 13.0.2.29 or later so managed Windows Agents receive the fixed build (Arctic Wolf cites Agent 13.0.3.1220); confirm Agent service/tray versions after upgrade; restrict interactive local access on Agent hosts until patched
Primary: Veeam KB4852 — vulnerabilities resolved in Backup & Replication 13.0.2 (CVE-2026-32996) · Vendor: Veeam — KB4852 patch advisory · CVE: CVE-2026-32996, CVE-2026-32997 · Arctic Wolf — UPDATE: active exploitation CVE-2026-32996 (16 Sep 2026); also THN 22 Sep
