Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteYes. CISA added three vulnerabilities in the Veritas Backup Exec agent to its Known Exploited Vulnerabilities (KEV) catalog on April 7, 2023, after evidence of exploitation in the wild. Mandiant linked attacks exploiting the flaws to Alphv, also known as BlackCat, ransomware actors. The federal patch deadline associated with that 2023 listing has passed; the vulnerabilities remain a reason to check affected systems and investigate any signs of compromise.
Which Backup Exec vulnerabilities did CISA list?
The three listed flaws are CVE-2021-27876, CVE-2021-27877, and CVE-2021-27878. They affect the Backup Exec agent’s SHA Authentication scheme. Veritas released fixes when the vulnerabilities were disclosed in March 2021; CISA added the CVEs to KEV on April 7, 2023, based on evidence that they had been exploited.
| CVE | Affected component | Reported impact |
|---|---|---|
| CVE-2021-27876 | Veritas Backup Exec agent, SHA Authentication scheme | The incident report describes the three flaws as capable of enabling arbitrary file access or arbitrary command execution; it does not map each impact to an individual CVE. |
| CVE-2021-27877 | Veritas Backup Exec agent, SHA Authentication scheme | The incident report describes the three flaws as capable of enabling arbitrary file access or arbitrary command execution; it does not map each impact to an individual CVE. |
| CVE-2021-27878 | Veritas Backup Exec agent, SHA Authentication scheme | The incident report describes the three flaws as capable of enabling arbitrary file access or arbitrary command execution; it does not map each impact to an individual CVE. |
What could an attacker do?
The reported impact was access to arbitrary files or execution of arbitrary commands. That is a serious risk for a backup environment: unauthorized access or command execution on a backup server or agent can undermine the confidentiality and integrity of backup data and may help an attacker progress toward ransomware deployment. The cited incident reporting establishes the technical impact, but does not provide a single version cutoff that applies to every Backup Exec installation.
How were the flaws connected to ransomware?
A Metasploit module for exploiting the vulnerabilities was released in September 2022, and exploitation attempts in the wild were observed the following month. Mandiant reported that Alphv (BlackCat) ransomware actors used the flaws for initial access. Veritas warned that a known exploit was available in the wild and could be used as part of a ransomware attack.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
SecurityWeek reported Mandiant’s 2023 estimate that roughly 8,500 Veritas Backup Exec instances were exposed to the internet. That is a historical estimate, not a current exposure count, and it does not indicate how many of those instances were vulnerable or compromised.
What did the CISA “must patch” listing mean?
CISA describes KEV as “the authoritative source of vulnerabilities that have been exploited in the wild” and recommends using the catalog to help prioritize vulnerability management. A KEV entry is an important patch-prioritization signal; it does not by itself mean that every organization was compromised or that every Backup Exec deployment was exposed.
Rank #2
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
For U.S. federal civilian agencies covered by Binding Operational Directive 22-01, the reported remediation deadline for these entries was April 28, 2023. That deadline is historical and applied to covered agencies. It was not a general deadline imposed on every private organization or Backup Exec user.
What should Backup Exec administrators do now?
- Find affected components. Inventory Backup Exec servers and agents, including systems that may be retired, rarely used, or managed by another team. Confirm whether the affected SHA Authentication component is present.
- Check and apply the vendor fix. Compare installed versions with Veritas’s fixes for the vulnerabilities, then apply the applicable patch or upgrade. Because the available reporting does not establish one universal version cutoff, use the vendor’s guidance for the specific Backup Exec release rather than relying on a guessed version number.
- Reduce unnecessary exposure. Remove internet access to Backup Exec services that do not need to be publicly reachable. Restrict access to required management paths and systems.
- Look for signs of misuse. Review authentication and command-execution logs for unexpected access or activity, especially around the period when exploitation was reported. Preserve relevant logs and other evidence if suspicious activity appears.
- Escalate suspected compromise. Coordinate incident response rather than treating an unexplained event as a routine patching issue. Assess whether backup data, backup-management systems, and recovery procedures can still be trusted.
- Verify recovery readiness. Confirm that backups needed for restoration are available and that recovery can be carried out safely. A patched server does not, on its own, establish that earlier activity caused no damage.
How to prioritize remediation across several systems
Prioritize systems where the affected component is present, the vendor fix is missing, and internet exposure or suspicious log activity raises the risk. Include recovery readiness in the decision: systems that manage backups deserve careful review because compromise could affect both production services and the ability to restore them. If the component is absent, document that finding; if exploitation is suspected, prioritize investigation and incident response alongside remediation.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Rank #4
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Rank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

