A local privilege-escalation flaw in Veeam Agent for Microsoft Windows is under active exploitation attempts following the public release of proof-of-concept code on 14 September, according to Arctic Wolf Labs. The bug, tracked as CVE-2026-32996, affects Veeam Agent for Microsoft Windows version 13.0.1.2067 and earlier, and lets a low-privileged local user elevate to NT AUTHORITY\SYSTEM by abusing how the backup agent’s service caches elevated session data. Veeam fixed the flaw in Veeam Backup & Replication 13.0.2.29, which also updates the affected agent to build 13.0.3.1220.

For a CISO, the notable part isn’t the CVSS score, it’s what the vulnerability is sitting inside. Backup agents run with elevated local privileges by design, on exactly the systems, servers, admin workstations, shared endpoints, where local access already carries outsized risk. Arctic Wolf is telling customers to prioritize patching on shared workstations and systems where a low-privileged account compromise could lead to full endpoint takeover, which describes a large share of any enterprise backup footprint. Exploitation requires local access, so this isn’t a remote, internet-facing emergency, but it collapses the distance between “a low-level account got phished” and “an attacker owns the box” on any machine still running the vulnerable agent.

The original insight here is about a pattern, not just this one bug: backup and endpoint-protection software increasingly runs with the kind of elevated local trust that used to be reserved for the operating system itself, which makes it a growing privilege-escalation target class in its own right, independent of the backup platform’s actual security record. Security teams that inventory patch status by “server vs. endpoint” rather than “what runs with elevated local privilege” are likely to miss agents like this one until exploitation is already public. CyberTech has covered a similar pattern in trust-critical infrastructure software this month, and continues to track how root-level flaws in security and management agents keep surfacing faster than patch cycles catch up.

Source: Arctic Wolf