Veeam Agent for Windows Local Privilege Escalation
Local privilege escalation in Veeam Agent for Microsoft Windows gives local attackers SYSTEM-level access. CVSS 7.3 high, confirmed exploited in the wild.
- Vendor
- Veeam
- Product
- Veeam Agent for Microsoft Windows
- CVSS
- 7.3
- EPSS (exploit probability)
- 0.2%
- Status
- exploited-in-wild
- Published
CVE-2026-32996 is a local privilege escalation in Veeam Agent for Microsoft Windows, rated CVSS 7.3 high. An attacker with existing local access can exploit the flaw to obtain SYSTEM-level control of the endpoint.
Arctic Wolf researchers identified this vulnerability as actively exploited in the wild as of September 2026. Veeam has released a patch; consult the NVD record for current version guidance.
The local-access prerequisite raises the CVSS score’s effective exploitability bar, but backup infrastructure warrants particular care: Veeam Agent hosts typically hold backup credentials, broad file-system access, and paths to other network segments. SYSTEM on such a host is a meaningful attacker position.
