Veeam Agent for Windows CVE-2026-32996 (CVSS 7.3) lets a local user reach SYSTEM by reusing session IDs written to logs that standard users can read. It affects version 26.6.4.2067 and earlier and is fixed in 13.0.3.1220. A public proof-of-concept appeared on 14 September and exploitation followed. Separately, Acronis fixed CVE-2026-87886 in its Backup plugin for cPanel/WHM — a privilege escalation caused by insecure file permissions, used in limited targeted attacks — in version 26.6.4 HF3, with 1.8.11 for the Plesk extension.
Neither is a remote, internet-wide hole. Both are privilege escalation, and that’s the point. An attacker who lands on a server as a low-privilege user looks for the fastest route to SYSTEM, and a backup agent — installed everywhere, running with high privilege, rarely on anyone’s patch list — is an attractive one. Control the backup layer and you can go after the very thing the business was counting on to recover.
Put backup agents in the same patch cycle as the operating system, with an owner and a version check. Keep backup management on credentials separate from the domain, keep at least one immutable copy that the agent itself can’t delete, and test restores on a schedule rather than in a crisis.
