Cyber Resilience

CVE-2026-21672

High

Published: 12 March 2026

Published
12 March 2026
Modified
10 May 2026
KEV Added
Patch
CVSS Score v3.1 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0022 12.6th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2026-21672 is a high-severity Insertion of Sensitive Information into Externally-Accessible File or Directory (CWE-538) vulnerability in Veeam Backup (inferred from references). Its CVSS base score is 8.8 (High).

Operationally, ranked at the 12.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability details

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-27173Shared CWE-538
CVE-2023-54346Shared CWE-538
CVE-2016-20024Shared CWE-538
CVE-2026-23838Shared CWE-538
CVE-2020-37104Shared CWE-538
CVE-2019-25706Shared CWE-538
CVE-2026-49298Shared CWE-538
CVE-2025-12059Shared CWE-538
CVE-2025-11079Shared CWE-538

Affected Assets

Veeam
Backup
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-538

Pre- and post-publication reviews prevent insertion of sensitive information into externally-accessible public locations.

addresses: CWE-538

Monitors for sensitive information placed in externally accessible files or directories.

addresses: CWE-538

The map shows if data actions result in sensitive information being placed in externally accessible locations.

addresses: CWE-538

Isolation and eradication reduce the ability to exploit sensitive information inserted into externally-accessible files or directories.

addresses: CWE-538

Approved categorization forces identification of externally accessible files that contain sensitive content so they receive proper protection.

addresses: CWE-538

The pre-implementation review identifies externally accessible files or directories containing PII and drives access restrictions or removal.

addresses: CWE-538

Tainting makes it possible to determine when sensitive data has been removed from externally accessible files or directories.

addresses: CWE-538

OPSEC practices stop placement of supply-chain information into locations accessible to external parties.

References