Critical Veeam flaw lets domain users run code on backup servers
Veeam has fixed a critical Backup & Replication vulnerability that can allow remote code execution on backup servers joined to an Active Directory domain. The flaw is tracked as CVE-2026-44963 and affects Veeam Backup & Replication version 12.3.2.4465 and all earlier version 12 builds.
The issue was disclosed in a Veeam security advisory published on June 9, 2026. Veeam rates the flaw Critical with a CVSS v4 score of 9.4 and says it can be exploited by an authenticated domain user.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Veeam fixed the vulnerability in build 12.3.2.4854. The companyโs release information page lists the June 8, 2026 build as the version that addresses CVE-2026-44963.
What makes CVE-2026-44963 dangerous
The flaw matters because backup servers often hold privileged access to critical infrastructure. If an attacker compromises a backup server, they may gain a path to sensitive data, backup repositories, restore operations, and systems needed during ransomware recovery.
The vulnerability does not require administrator privileges. Veeam says an authenticated domain user can trigger remote code execution on the Backup Server, which lowers the bar for attackers who already have basic access inside a Windows domain.
BleepingComputer reported that there were no public reports of active exploitation at the time of disclosure. Veeam still warned that attackers often reverse-engineer patches after public advisories are released, making fast patching important.
| Vulnerability | Details |
|---|---|
| CVE ID | CVE-2026-44963 |
| Product | Veeam Backup & Replication |
| Impact | Remote code execution on the Backup Server |
| Severity | Critical |
| CVSS v4 score | 9.4 |
| Required access | Authenticated domain user |
| Fixed build | 12.3.2.4854 |
Only domain-joined backup servers are affected
Veeam says CVE-2026-44963 only affects domain-joined backup servers. Backup servers that do not belong to an Active Directory domain are not affected by this specific flaw.
That distinction is important for companies that joined their backup infrastructure to a production domain for easier administration. In that setup, a low-privileged domain account can become more dangerous if attackers steal credentials through phishing, malware, or another compromised endpoint.
The Veeam security best practice guide recommends placing Veeam components in a management workgroup or a separate management domain in another Active Directory forest for the most secure deployment. The goal is to prevent the backup system from depending on the same environment it must protect.
- Domain-joined Veeam Backup & Replication v12 servers are affected.
- Veeam Backup & Replication 12.3.2.4465 and earlier version 12 builds are affected.
- Version 13.x builds are not affected because of architectural changes.
- Unsupported product versions were not tested and should be treated as potentially vulnerable.
Veeam says version 13.x is not affected
Veeam says the flaw does not affect any Veeam Backup & Replication 13.x build because of architectural changes introduced in version 13. However, organizations still running version 12 should not wait for a larger upgrade project if they can install the fixed 12.3.2.4854 build now.
The official Veeam advisory credits Sina Kheirkhah of watchTowr for reporting the issue. It also warns customers that public patch disclosure gives attackers an opportunity to compare vulnerable and fixed builds.
Veeamโs 12.3 release notes show that build 12.3.2.4854 includes the security fix and also adds Veeam Agent for Linux support updates. Admins can check their installed build number from the Veeam Backup & Replication Console under Help and About.
| Version | Status | Action |
|---|---|---|
| 12.3.2.4465 and earlier version 12 builds | Affected | Update to 12.3.2.4854 |
| 12.3.2.4854 | Fixed | Deploy after normal testing |
| 13.x | Not affected by this flaw | Keep current with regular security updates |
| Unsupported versions | Not formally tested | Treat as vulnerable and upgrade |
Why backup servers need urgent protection
Backup platforms are high-value targets during ransomware attacks. Attackers often try to steal backups, delete restore points, disable recovery tools, or use backup infrastructure to move deeper into a network.
The risk is not theoretical. The CISA Known Exploited Vulnerabilities catalog lists older Veeam Backup & Replication flaws, including CVE-2024-40711 and CVE-2023-27532, that have been exploited in real attacks.
BleepingComputerโs report also notes that ransomware operators have repeatedly targeted Veeam backup servers because compromising them can help block restoration and increase pressure on victims.
What administrators should do now
Administrators should first identify every Veeam Backup & Replication server running version 12. Then they should confirm whether the server is domain-joined and whether it runs build 12.3.2.4465 or an earlier version 12 build.
Organizations should upgrade affected systems to build 12.3.2.4854 as soon as testing allows. If immediate patching is not possible, teams should restrict access to the backup server, monitor authentication activity, and limit which domain users can reach Veeam services over the network.
- Install Veeam Backup & Replication 12.3.2.4854 on affected version 12 deployments.
- Check whether the Veeam Backup Server is joined to a production domain.
- Review domain user access to backup infrastructure.
- Restrict network access to Veeam services from ordinary workstations.
- Monitor for unusual logins, service activity, privilege escalation, and lateral movement.
- Review backup server placement against the workgroup or domain guidance.
- Check older Veeam exposure history through the CISA KEV catalog.
CVE-2026-44963 should receive high priority in enterprise patch queues because it affects a system attackers often seek during ransomware operations. The safest response is to patch affected Veeam 12 deployments, reduce domain exposure, and treat backup infrastructure as a privileged security boundary.
FAQ
CVE-2026-44963 is a critical Veeam Backup & Replication vulnerability that can allow remote code execution on a backup server by an authenticated domain user.
The vulnerability affects Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds. Veeam says version 13.x builds are not affected by this specific flaw.
No. Veeam says the vulnerability only affects domain-joined backup servers. Servers not joined to an Active Directory domain are not affected by this specific issue.
Veeam fixed CVE-2026-44963 in Veeam Backup & Replication 12.3.2.4854. Affected version 12 deployments should upgrade to that build or later.
Backup servers can hold access to critical data and recovery systems. If attackers compromise them, they may delete backups, steal data, or make recovery from ransomware harder.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages