< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 4 sources · 28 days · First seen · Last updated

Windows agent software security vulnerabilities

Overview

Security vulnerabilities have been identified in Windows-based agent software from WatchGuard and Veeam.

WatchGuard disclosed two critical flaws in its Windows Agent, affecting versions prior to 1.25.13.0000. These include CVE-2026-57910, an improper authentication flaw in the UDP discovery and command service, and CVE-2026-57909, a path traversal flaw. Both could allow unauthenticated attackers to execute arbitrary code with elevated privileges. WatchGuard reported no known active exploitation at the time of disclosure.

Veeam Agent for Windows is also affected by CVE-2026-32996, a vulnerability that allows local privilege escalation to SYSTEM-level access. While a patch was released in May 2026, the release of a public exploit on GitHub has renewed concerns. The flaw affects version 13.0.2.1102 and earlier versions in the 13 branch, particularly posing a risk on shared workstations or servers where administration sessions remain open.

Entities

Veeam · Arctic Wolf · WatchGuard

Timeline

  1. [TECHNOLOGY] 2 sources
    Veeam Agent for Windows vulnerability allows local privilege escalation

    A public exploit for CVE-2026-32996 allows local users to gain SYSTEM privileges on unpatched Veeam Agent for Windows systems. Users are urged to update to the latest version immediately.

  2. [TECHNOLOGY] 2 sources
    WatchGuard discloses critical vulnerabilities in Windows Agent

    WatchGuard disclosed two critical vulnerabilities (CVE-2026-57910 and CVE-2026-57909) in its Windows Agent that could allow unauthenticated remote code execution with SYSTEM privileges.

Sources

cybernoz.com · invitehealth.substack.com · it-connect.fr · korben.info