# Attackers exploit Veeam Agent flaw to gain SYSTEM-level Windows access

_Published Tuesday, September 22, 2026 at 6:07 AM EDT · Security · Latest · Tier 2 — Notable_

![Attackers exploit Veeam Agent flaw to gain SYSTEM-level Windows access — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjj9eouOxeSvnYBzl5A8tWvEQ4w_CCx94YcFmpBAXXqHWNqvFBWj4vOgeZdHYAf0MU-chY63biCpHDnzRC0pwR7s3pTdQAWwPAVI-olRZuBwG0ilgAxnIY_1KofE3cpuA8lKOE01U26EFHYE_nLrXYXOWl47G1KaoFTZ5UOO81Cw0Kb20pFSfAc1b9i9E_K/s1700-nu-rw-lo-l85-e365/veeam.jpg)

Arctic Wolf warned that attackers are exploiting CVE-2026-32996, a local privilege-escalation flaw in Veeam Agent for Microsoft Windows that can give a user with local access SYSTEM-level control. The backup service caches an elevated administrator identity against a client-controlled session identifier without binding it to the requesting user or connection.

Standard users can read valid elevated identifiers from a Veeam log file and reuse them to execute commands with the highest Windows privileges. The flaw carries a CVSS score of 7.3, and exploitation still requires local access to an affected endpoint.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html)

---
Canonical: https://techandbusiness.org/newswire/XzrtLt6jxG-sEorq-HXhiM
Published: 2026-09-22T10:07:05.598Z
Story chronology: 2026-09-22T05:31:59.000Z
Retrieved: 2026-09-22T12:12:28.340Z
Publisher: Tech & Business (techandbusiness.org)
