← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 22, 2026 · 11:17via CyberPress

Hackers Exploit Veeam Agent Flaw to Gain SYSTEM Privileges on Windows

Brief

A newly disclosed active exploitation of a critical local privilege escalation flaw in Veeam Agent for Microsoft Windows that enables attackers to elevate low-privileged access to NT AUTHORITY\SYSTEM on vulnerable endpoints.

Tracked as CVE-2026-32996 , the vulnerability affects Veeam Agent for Microsoft Windows version 13.

  • 1. 2067 and earlier Version 13 builds.

Public technical analysis and proof-of-concept exploit code became available on September 14, significantly increasing the risk that threat actors and post-exploitation operators will adopt the flaw in real-world intrusion chains.

Hackers Exploit Veeam Agent Flaw

The vulnerability exists in the Veeam Endpoint Backup service, which manages elevated client sessions over the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe .

Read more on CyberPress