Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Windows 11 Update KB5094126 Freezes Systems, Forces BitLocker
June 15, 2026
Critical Wazuh Flaw Lets Attackers Tamper Alerts &
June 15, 2026
SecSuite: AI Tool for OSINT, Web AI-powered Security
June 15, 2026
Home/CyberSecurity News/Critical Veeam Vulnerability Allows RCE on Backup Servers
CyberSecurity News

Critical Veeam Vulnerability Allows RCE on Backup Servers

Veeam Backup & Replication, a leading enterprise backup solution extensively deployed across the globe, is impacted by a newly disclosed critical security vulnerability. Tracked as...

Marcus Rodriguez
Marcus Rodriguez
June 9, 2026 2 Min Read
18 0

Veeam Backup & Replication, a leading enterprise backup solution extensively deployed across the globe, is impacted by a newly disclosed critical security vulnerability.

Tracked as CVE-2026-44963, the flaw enables authenticated domain users to execute arbitrary code remotely on backup servers, posing severe risks to organizations relying on Veeam for data protection and recovery operations.

The vulnerability carries a CVSS v4 score of 9.4, placing it firmly in the critical severity tier. Discovered and reported by security researcher Sina Kheirkhah (@SinSinology) of WatchTowr, CVE-2026-44963 allows remote code execution (RCE) on the Backup Server by any authenticated domain user, a notably low privilege requirement that dramatically widens the attack surface.

Veeam Vulnerability Allows RCE Attacks

Crucially, this vulnerability only impacts domain-joined backup servers. Organizations running Veeam in a workgroup configuration rather than an Active Directory domain environment are not affected by this specific flaw.

Veeam’s own security best practice guidance has long recommended evaluating workgroup versus domain configurations precisely because domain-joined deployments expand the potential attacker pool.

The vulnerability affects Veeam Backup & Replication versions 12 through 12.3.2.4465, and all earlier versions of 12. This encompasses a wide range of deployments across the following major releases:

  • Veeam Backup & Replication 12
  • Veeam Backup & Replication 12.1
  • Veeam Backup & Replication 12.2
  • Veeam Backup & Replication 12.3, 12.3.1, and 12.3.2 (prior to build 4854)

Notably, Veeam Backup & Replication version 13.x is not affected due to architectural changes introduced in that release cycle. Unsupported product versions were not formally tested but should be assumed vulnerable.

Veeam has addressed the vulnerability in Veeam Backup & Replication 12.3.2.4854, released June 9, 2026, and available via Veeam KB4696. Organizations should prioritize upgrading immediately.

Veeam explicitly warned that once a vulnerability patch is publicly disclosed, threat actors routinely reverse-engineer the fix to develop exploits targeting unpatched systems.

Given the critical CVSS score and the relatively low bar of “authenticated domain user” access needed to trigger RCE, exploitation attempts against unpatched deployments are highly probable in the near term.

  • Upgrade to Veeam Backup & Replication 12.3.2.4854 immediately
  • Audit whether backup servers are domain-joined and evaluate migrating to a workgroup configuration per Veeam’s security best practices
  • Monitor for suspicious lateral movement or privilege escalation activity originating from backup infrastructure
  • Review domain user access controls on all Veeam Backup Server instances

Backup servers are high-value targets for ransomware operators, making rapid patching of CVE-2026-44963 a top remediation priority for enterprise security teams.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchransomwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

North Korean Hackers Abuse GitHub Repos to Korea-Aligned Repositories

Next Post

Microsoft Patch Tuesday June 2026: 1 Vulnerabilities Fixed

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Palo Alto: GlobalProtect VPN Vulnerability Act Warns Actively
June 15, 2026
152 Chrome Extensions Maliciously Hide Ad Tracking
June 14, 2026
Maine AG Takes Data Breach Portal Offline After Fake
June 14, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us