Proof-of-Concept Exploit Code Released for Veeam Vulnerability CVE-2026-32996
Exploitation of Veeam Agent for Microsoft Windows vulnerability could allow local privilege escalation to SYSTEM privileges
Summary
Exploitation of Veeam Agent for Microsoft Windows vulnerability could allow local privilege escalation to SYSTEM privileges
Affected platforms
The following platforms are known to be affected:
Threat details
Proof-of-Concept exploit code for CVE-2026-32996 released
Public technical details and proof-of-concept exploit code for CVE-2026-32996 were reportedly disclosed on 14 September 2026.
The NHS England National CSOC assess that future exploitation of this vulnerability is likely.
Introduction
Proof-of-concept exploit code was released for a Veeam Agent for Microsoft Windows vulnerability that was originally reported by Veeam in May 2026.
Successful exploitation could allow a low-privileged local user to gain NT AUTHORITY\SYSTEM privileges on an affected endpoint.
- CVE-2026-32996 - Insertion of Sensitive Information into Log File vulnerability leading to local privilege escalation - CVSSv4.0: 7.3
Remediation advice
Affected organisations are strongly encouraged to review Veeam Security Bulletin KB4852 and apply the relevant update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 22 September 2026 3:00 pm