Vulnerability threat dossier

CVE-2026-32996

VeeamBackup and Replication

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

VTP deterministic threat24.5of 100 · CVSS excluded

VTP analyst assessment

Veeam Agent for Microsoft Windows local privilege escalation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence60%
Public exploitation · VTP factREPORTED

Assessment

A public report describes CVE-2026-32996 as under active exploitation. The flaw affects Veeam Agent for Microsoft Windows and requires local access with low privileges, allowing privilege escalation.

Why it matters

  • An attacker who already obtains a low-privileged Windows foothold could gain higher privileges.
  • The report makes timely remediation more important on systems running the affected agent.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The exploitation report is press reporting with unknown source independence.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Veeam Agent for Microsoft Windows, apply Veeam's available fix promptly.

AI baseline history (2)
  1. BASELINE ASSESSED
    Veeam Agent for Microsoft Windows local privilege escalationgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Veeam Agent for Windows local privilege escalationgpt-5.6-terra · low
Technical severityHIGHCVSS 7.3 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.005th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:4ad642232a68ef791a2df2973aefc15210bc72e3775cabf71e836b740010fc72ACTIVE
Evidence
04

Event history

Threat timeline

  1. 05:3122 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating

CVE-2026-32996CVE-2026-7273
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score24.5vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.03 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency10 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
7.3 · HIGH
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-532
CPE records
0
Deterministic history records
4
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.