Critical Veeam Backup & Replication Vulnerability Allows RCE Attacks
Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-44963, has been identified in Veeam Backup & Replication. The flaw allows any authenticated domain user to execute...
Key Takeaways
- A critical remote code execution (RCE) vulnerability, CVE-2026-44963, has been identified in Veeam Backup & Replication.
- The flaw allows any authenticated domain user to execute arbitrary code on affected backup servers, posing a significant risk.
- The vulnerability impacts Veeam Backup & Replication versions 12 through 12.3.2.4465 and earlier versions of 12.
- Veeam has released a patch, version 12.3.2.4854, and urges immediate upgrades for all affected organizations.
Critical RCE Flaw Uncovered in Veeam Backup & Replication
A severe security vulnerability has been disclosed in Veeam Backup & Replication, a widely adopted enterprise solution for data protection. This critical flaw could enable remote code execution on backup servers, threatening the integrity and availability of crucial organizational data.
Table Of Content
Designated as CVE-2026-44963, the vulnerability carries a CVSS v4 score of 9.4, firmly categorizing it as critical. Security researcher Sina Kheirkhah (@SinSinology) from WatchTowr discovered and reported the issue. The vulnerability allows any authenticated domain user to execute arbitrary code on the Backup Server. This low-privilege requirement significantly broadens the potential attack surface, making it a high-priority concern for cybersecurity teams.
Vulnerability Details and Affected Versions
The RCE vulnerability specifically targets Veeam backup servers integrated into Active Directory domains. Organizations utilizing Veeam in a workgroup configuration are not susceptible to this particular flaw. Veeam’s long-standing security guidance has recommended careful evaluation between workgroup and domain configurations, partly due to the expanded attacker pool inherent in domain-joined deployments.
The vulnerability affects a broad spectrum of Veeam Backup & Replication deployments, encompassing:
- Veeam Backup & Replication 12
- Veeam Backup & Replication 12.1
- Veeam Backup & Replication 12.2
- Veeam Backup & Replication 12.3, 12.3.1, and 12.3.2 (specifically builds prior to 4854)
It is important to note that Veeam Backup & Replication version 13.x is unaffected, thanks to architectural changes introduced in that release cycle. While unsupported product versions were not officially tested, they should be presumed vulnerable to this critical flaw.
Patch Availability and Urgency
Veeam has released a fix for CVE-2026-44963 in Veeam Backup & Replication 12.3.2.4854, made available on June 9, 2026, and detailed in Veeam KB4696. The vendor strongly advises organizations to upgrade their systems immediately.
Veeam has issued a stark warning: the public disclosure of a vulnerability patch frequently prompts threat actors to reverse-engineer the fix to develop exploits targeting unpatched systems. Given the critical CVSS score and the minimal requirement of an “authenticated domain user” for RCE, the likelihood of imminent exploitation attempts against vulnerable deployments is exceptionally high.
Backup servers represent highly attractive targets for ransomware groups and other malicious actors. Consequently, the prompt patching of CVE-2026-44963 should be a top priority for all enterprise security teams.
What You Should Do
- Immediately upgrade to Veeam Backup & Replication 12.3.2.4854.
- Review whether your backup servers are domain-joined and consider migrating to a workgroup configuration, aligning with Veeam’s security best practices, if appropriate for your environment.
- Implement enhanced monitoring for any suspicious lateral movement or privilege escalation activities originating from your backup infrastructure.
- Conduct a thorough audit of domain user access controls across all Veeam Backup Server instances to ensure least privilege principles are enforced.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.