{"id":16414,"date":"2026-06-06T12:20:56","date_gmt":"2026-06-06T12:20:56","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=16414"},"modified":"2026-07-09T16:26:54","modified_gmt":"2026-07-09T16:26:54","slug":"when-the-backup-server-itself-becomes-the-vulnerability","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/06\/06\/when-the-backup-server-itself-becomes-the-vulnerability\/","title":{"rendered":"When the Backup Server Itself Becomes the Vulnerability"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 min read<\/p>\n<p><strong>Veeam has closed two high-severity vulnerabilities in its backup software. Affected are the Veeam Agent for Microsoft Windows and the Veeam Software Appliance on Linux-precisely the component that is supposed to carry the recovery load in an emergency. Anyone using Backup &#038; Replication up to version 13.0.1.2067 should update to 13.0.2.29 without delay.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Two high-severity gaps in the backup stack.<\/strong> The Veeam Agent for Windows (CVE-2026-32996) and the Linux appliance (CVE-2026-32997) are affected; both are patched by the current Backup &#038; Replication security update.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">No remote access out of thin air.<\/strong> Both vulnerabilities require authentication or local access. They become especially dangerous if a backup admin account is already in the wrong hands.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">The backup server is the wrong place for open flanks.<\/strong> It is the last line of defense against ransomware. A privilege escalation there carries particular weight.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#b8c5ce;margin:20px 0 32px 0;border-top:1px solid rgba(230,227,218,0.12);border-bottom:1px solid rgba(230,227,218,0.12);padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related:<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/05\/3-2-1-1-0-restore-test\/\" style=\"color:#333;text-decoration:underline;\">Backup vs. Ransomware: 3-2-1-1-0<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/13\/ransomware-post-mortem-what-manufacturers-really-learned\/\" style=\"color:#333;text-decoration:underline;\">Ransomware Reboot: What Really Breaks<\/a><\/p>\n<p><strong>What is Veeam Backup &#038; Replication?<\/strong> Veeam Backup &#038; Replication is widely used software that lets companies back up servers, virtual machines, and endpoints and restore them in an emergency. The backup server centrally manages these backups. If it fails or is compromised, the entire recovery process grinds to a halt.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What these two vulnerabilities actually mean<\/h2>\n<p>Veeam has closed the vulnerabilities with a security update for Backup &#038; Replication and documented them in a dedicated advisory database. Both are rated high severity, but they affect different components and require different conditions.<\/p>\n<p>The first vulnerability, tracked as CVE-2026-32996, affects the Veeam Agent for Microsoft Windows. It allows an attacker with local access to escalate privileges on the system. Veeam assigns it a CVSS score of 7.3. A local privilege escalation becomes dangerous when an attacker already has a foothold on the machine and wants to climb to administrator level from there.<\/p>\n<p>The second vulnerability, CVE-2026-32997, resides in the Veeam Software Appliance on Linux. Here, an authenticated user with the Backup Administrator role can write arbitrary files to the server and prepare follow-up attacks. Veeam rates it at CVSS 8.6-even higher than the Windows flaw. The prerequisite is a valid backup admin account. This condition shifts the risk: as long as backup admin accounts remain secure, the flaw is hard to exploit. A compromised privileged account turns it into a dangerous lever.<\/p>\n<div class=\"evm-stat-highlight\" style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">2<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin-left:auto;margin-right:auto;line-height:1.5;\">high-severity vulnerabilities hit the Veeam Agent for Windows and the Linux appliance. Both are fixed by updating to Backup &#038; Replication 13.0.2.29.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: Veeam Security Advisory (KB4852), heise security<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">Why the backup server is a particularly sensitive target<\/h2>\n<p>The sobering truth first: neither of the two vulnerabilities can be exploited remotely without authentication. Yet the assessment changes when you consider which system is involved here.<\/p>\n<p>The backup server is the fallback space for emergencies. When production systems are encrypted, recoverability determines whether downtime lasts days or weeks. That\u2019s exactly why ransomware groups target backups first: deleting or tampering with the backup removes the victim\u2019s emergency exit. Privilege escalation or write access on this system, in this logic, strikes at the heart of defense.<\/p>\n<p>There\u2019s a second point. Backup servers often run in the background, are rarely rebooted, and even less frequently updated because an outage interrupts the backup chain. This inertia is understandable, but it\u2019s also why known Veeam gaps have been exploited long after patches were released. An available update is useless if it isn\u2019t applied.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">How urgent is the patch really?<\/h2>\n<p>Honestly assessed, the urgency sits in the mid-range, not in the red zone of an emergency patch. Both vulnerabilities require a foothold inside the system or a privileged account; mass automated exploitation from the internet isn\u2019t possible. A company with cleanly separated backup-admin accounts and current endpoint patch levels has some breathing room.<\/p>\n<p>Still, the update belongs on the next maintenance window list, not in the queue for next quarter. The deciding factor is the combination: backup servers are a prime target, privileged accounts are routinely hijacked in real attacks, and that\u2019s when a medium-severity gap becomes a sharp tool. If you\u2019re already planning a maintenance window, pull the Veeam update forward.<\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What admins should do now<\/h2>\n<p>The sequence is straightforward and avoids knee-jerk reactions. Four steps cover the immediate need.<\/p>\n<div class=\"evm-timeline\" style=\"margin:28px 0;border:1px solid rgba(230,227,218,0.12);border-radius:6px;overflow:hidden;\">\n<div style=\"background:#003340;color:#fff;padding:12px 18px;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.14em;\">Four steps after the Veeam update<\/div>\n<div style=\"padding:8px 0;\">\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:150px;font-weight:700;color:#69d8ed;\">Check version<\/div>\n<div style=\"color:#333;line-height:1.55;\">Determine the current build of Backup &#038; Replication. All releases up to and including 13.0.1.2067 are affected and should go on the list.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:150px;font-weight:700;color:#69d8ed;\">Apply update<\/div>\n<div style=\"color:#333;line-height:1.55;\">Upgrade to 13.0.2.29 during a scheduled maintenance window and run a functional test of the backup jobs afterward.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;border-bottom:1px solid #f0f0f0;\">\n<div style=\"min-width:150px;font-weight:700;color:#69d8ed;\">Limit backup admin<\/div>\n<div style=\"color:#333;line-height:1.55;\">Assign the Backup Administrator role only to a small set of accounts, protected by multi-factor authentication on the console. Both gaps require precisely these accounts or local access.<\/div>\n<\/p><\/div>\n<div style=\"display:flex;gap:18px;padding:12px 20px;\">\n<div style=\"min-width:150px;font-weight:700;color:#69d8ed;\">Monitor access<\/div>\n<div style=\"color:#333;line-height:1.55;\">Log logins and write operations on the backup server and review for anomalies. Knowing the baseline lets you spot deviations sooner.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p>None of these steps is labor-intensive, and the most critical is the second one. A patch sitting available in the maintenance backlog protects no one. With backup servers, the effort is worth bringing the maintenance window forward.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Which Veeam versions are affected by the vulnerabilities?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">All releases of Veeam Backup &#038; Replication up to and including version 13.0.1.2067 are affected. Version 13.0.2.29 closes both gaps. Users on older builds should schedule the update promptly.<\/p>\n<\/details>\n<details>\n<summary><strong>Can the vulnerabilities be exploited remotely without authentication?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. CVE-2026-32996 requires local access to the Windows system, while CVE-2026-32997 demands an authenticated account with the Backup Administrator role. An attacker would therefore need a foothold in the system or a compromised privileged account. This reduces the immediate urgency but does not eliminate the patching obligation.<\/p>\n<\/details>\n<details>\n<summary><strong>Which products are specifically affected?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The first vulnerability impacts the Veeam Agent for Microsoft Windows, while the second affects the Veeam Software Appliance on Linux servers. Both are part of the Backup &#038; Replication ecosystem, which is why the central backup software\u2019s security update delivers the fix.<\/p>\n<\/details>\n<details>\n<summary><strong>What is the most critical immediate action?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Apply the available update during a scheduled maintenance window and then test the backup jobs. As a precaution, restrict Backup Administrator privileges and protect them with multi-factor authentication.<\/p>\n<\/details>\n<details>\n<summary><strong>Why is the backup server an attractive target for attackers?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Because it underpins recovery. Ransomware groups routinely attempt to delete or manipulate backups first, removing the victim\u2019s escape route. A vulnerability enabling privilege escalation or write access on this system is therefore more severe than on a typical endpoint.<\/p>\n<\/details>\n<h3>Editorial reading recommendations<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/bsi-warns-against-unpatched-ivanti-systems\/\">BSI warns of unpatched Ivanti systems<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/15\/ransomware-playbook-2026-what-security-teams-really-decide\/\">Ransomware: NIS2 reporting deadlines put pressure on security teams<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/01\/cve-2026-3854-github-enterprise-rce-git-push-patch-pflicht\/\">Git push is enough for RCE on GitHub Enterprise servers<\/a><\/li>\n<\/ul>\n<div style=\"margin:40px 0 24px 0;\">\n<!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/bsi-warns-against-unpatched-ivanti-systems\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/ivanti-epmm-zero-days-cve-2025-4427-und-cve-2025-4428-was-kritis-betreiber-jetzt-tun-muessen-cover-hero-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">BSI Warns Against Unpatched Ivanti Systems<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/15\/ransomware-playbook-2026-what-security-teams-really-decide\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/04\/st-15-04-ransomware-playbook-72h-2026-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Ransomware Playbook 2026: Security Teams\u2018 First 72h Decisions<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/01\/cve-2026-3854-github-enterprise-rce-git-push-patch-pflicht\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/cve-2026-3854-github-enterprise-rce-cover-hero-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Git Push Leads to RCE on GitHub<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/03\/25\/container-supply-chain-security-how-it-teams-can-secure-their-software-supply-ch\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-container-supply-chain-security-wie-it-t-655299.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Container Supply Chain Security: IT Teams Secure Software Chains<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/supply-chain-transparency-why-coos-cant-steer-without-real-time-data-in-2026\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-lieferketten-auf-der-vorstandsagenda-war-83952600-250x187.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Supply Chain Transparency: Why COOs Can\u2019t Steer Without Real-Time Data in 2026<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/when-the-update-itself-becomes-an-entry-point\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-lieferkettenangriff-software-mittelstand-72660027-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">When the update itself becomes an entry point<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"Veeam Security Update: Two high-severity vulnerabilities affect Veeam Agent for Windows and the Linux Appliance. What admins need to patch now.","protected":false},"author":50,"featured_media":16373,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"Veeam security update","_yoast_wpseo_title":"When the Backup Server Itself Becomes the Vulnerability","_yoast_wpseo_metadesc":"Veeam security update: Patch two critical vulnerabilities in Veeam Agent for Windows & Linux Appliance now!","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-16414","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":16309,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/16414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=16414"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/16414\/revisions"}],"predecessor-version":[{"id":21172,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/16414\/revisions\/21172"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/16373"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=16414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=16414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=16414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}