Vulnerability
Published 2026-09-16
Verified 2026-09-22

Veeam Agent for Windows LPE CVE-2026-32996 (CVSS 7.3); Arctic Wolf active exploitation after public PoC

Veeam KB4852 documents CVE-2026-32996, a local privilege escalation in Veeam Agent for Microsoft Windows: a low-privileged local user can obtain SYSTEM by abusing elevated session UIDs cached against a client-controlled session UID on the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe (UIDs readable from C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log). Vendor CVSS 4.0 score 7.3 High (AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). Affected: Agent builds through 13.0.1.2067 and earlier version-13 builds. Fixed starting with Veeam Backup & Replication 13.0.2.29 (Arctic Wolf: that upgrade also brings Agent build 13.0.3.1220). Arctic Wolf (16 September 2026) reports public PoC details released 14 September 2026 and warns of active exploitation attempts — prioritise shared workstations, admin endpoints, and multi-user hosts. Same KB also ships CVE-2026-32997 (Backup Administrator arbitrary file write on Linux Veeam Software Appliance; CVSS 4.0 8.6) fixed in the same 13.0.2.29 build. Primary: Veeam KB4852; exploitation context: Arctic Wolf; wire: The Hacker News 22 Sep 2026.

Product
Veeam Agent for Microsoft Windows (managed via Veeam Backup & Replication 13.x)
Versions
Affected: Veeam Agent for Microsoft Windows 13.0.1.2067 and earlier version-13 builds (per KB4852 / Arctic Wolf). Fixed: upgrade Veeam Backup & Replication to 13.0.2.29 or later (Agent fixed build 13.0.3.1220 per Arctic Wolf).
CVSS
(CVSS 4.0 High; Veeam)
Exploited in Australia?
unknown
Patch to
Upgrade Veeam Backup & Replication to 13.0.2.29 or later so managed Windows Agents receive the fixed build (Arctic Wolf cites Agent 13.0.3.1220); confirm Agent service/tray versions after upgrade; restrict interactive local access on Agent hosts until patched

Primary: Veeam KB4852 — vulnerabilities resolved in Backup & Replication 13.0.2 (CVE-2026-32996) · Vendor: Veeam — KB4852 patch advisory · CVE: CVE-2026-32996, CVE-2026-32997 · Arctic Wolf — UPDATE: active exploitation CVE-2026-32996 (16 Sep 2026); also THN 22 Sep

vulnerabilities cloud identity