Skip to main content

Proof-of-Concept Exploit Code Released for Veeam Vulnerability CVE-2026-32996

Exploitation of Veeam Agent for Microsoft Windows vulnerability could allow local privilege escalation to SYSTEM privileges

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Exploitation of Veeam Agent for Microsoft Windows vulnerability could allow local privilege escalation to SYSTEM privileges


Threat details

Proof-of-Concept exploit code for CVE-2026-32996 released

Public technical details and proof-of-concept exploit code for CVE-2026-32996 were reportedly disclosed on 14 September 2026.

The NHS England National CSOC assess that future exploitation of this vulnerability is likely.


Introduction

Proof-of-concept exploit code was released for a Veeam Agent for Microsoft Windows vulnerability that was originally reported by Veeam in May 2026. 

Successful exploitation could allow a low-privileged local user to gain NT AUTHORITY\SYSTEM privileges on an affected endpoint.

  • CVE-2026-32996 - Insertion of Sensitive Information into Log File vulnerability leading to local privilege escalation - CVSSv4.0: 7.3

Remediation advice

Affected organisations are strongly encouraged to review Veeam Security Bulletin KB4852 and apply the relevant update as soon as possible.


Definitive source of threat updates


Last edited: 22 September 2026 3:00 pm