Critical RCE Vulnerability in Veeam Backup Exposes Organizations to Attacks

Critical RCE Vulnerability in Veeam Backup Exposes Organizations to Attacks

First seen 9 Jun 2026, 13:25 UTC Digital.Nhs.Ukwww.veeam.comBleepingcomputerbp.veeam.comCybersecuritynews+4 90% similarity 72.0

Article Content

Browse articles
ThreatCluster

Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts versions 12.3.2.4465 and earlier, with a patch available in version 12.3.2.4854. Many organizations have joined their Veeam servers to a Windows domain, contrary to best practices, making them vulnerable to exploitation. Although no active exploitation has been reported, the potential for attackers to develop exploits following the patch release is significant. Ransomware gangs have historically targeted Veeam servers to hinder recovery efforts and steal sensitive data. Veeam's products are widely used, with over 550,000 customers globally, including a large percentage of Fortune 500 companies. Security teams are urged to apply the latest updates immediately to mitigate risks.

Key Points: • CVE-2026-44963 allows remote code execution by low-privileged domain users on Veeam servers. • Veeam recommends against joining backup servers to a Windows domain, yet many organizations have done so. • A patch is available in version 12.3.2.4854, but organizations are urged to update immediately to prevent exploitation.

ThreatCluster AI

Timeline

2024-09-07
CVE-2024-40711 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-09
CVE-2026-44963 published
Veeam disclosed a critical vulnerability allowing remote code execution on backup servers by authenticated domain users.
Bleepingcomputer
2026-06-09
Patch released for Veeam Backup & Replication
Veeam released version 12.3.2.4854 to address the critical RCE vulnerability affecting earlier versions.
Bleepingcomputer
Recent
Ransomware gangs target Veeam servers
Ransomware groups have historically exploited Veeam vulnerabilities to steal data and disrupt recovery efforts.
Bleepingcomputer

Community

Browse all →