Critical Veeam flaw lets domain users run code on backup servers


Veeam has fixed a critical Backup & Replication vulnerability that can allow remote code execution on backup servers joined to an Active Directory domain. The flaw is tracked as CVE-2026-44963 and affects Veeam Backup & Replication version 12.3.2.4465 and all earlier version 12 builds.

The issue was disclosed in a Veeam security advisory published on June 9, 2026. Veeam rates the flaw Critical with a CVSS v4 score of 9.4 and says it can be exploited by an authenticated domain user.

Veeam fixed the vulnerability in build 12.3.2.4854. The companyโ€™s release information page lists the June 8, 2026 build as the version that addresses CVE-2026-44963.

What makes CVE-2026-44963 dangerous

The flaw matters because backup servers often hold privileged access to critical infrastructure. If an attacker compromises a backup server, they may gain a path to sensitive data, backup repositories, restore operations, and systems needed during ransomware recovery.

The vulnerability does not require administrator privileges. Veeam says an authenticated domain user can trigger remote code execution on the Backup Server, which lowers the bar for attackers who already have basic access inside a Windows domain.

BleepingComputer reported that there were no public reports of active exploitation at the time of disclosure. Veeam still warned that attackers often reverse-engineer patches after public advisories are released, making fast patching important.

VulnerabilityDetails
CVE IDCVE-2026-44963
ProductVeeam Backup & Replication
ImpactRemote code execution on the Backup Server
SeverityCritical
CVSS v4 score9.4
Required accessAuthenticated domain user
Fixed build12.3.2.4854

Only domain-joined backup servers are affected

Veeam says CVE-2026-44963 only affects domain-joined backup servers. Backup servers that do not belong to an Active Directory domain are not affected by this specific flaw.

That distinction is important for companies that joined their backup infrastructure to a production domain for easier administration. In that setup, a low-privileged domain account can become more dangerous if attackers steal credentials through phishing, malware, or another compromised endpoint.

The Veeam security best practice guide recommends placing Veeam components in a management workgroup or a separate management domain in another Active Directory forest for the most secure deployment. The goal is to prevent the backup system from depending on the same environment it must protect.

  • Domain-joined Veeam Backup & Replication v12 servers are affected.
  • Veeam Backup & Replication 12.3.2.4465 and earlier version 12 builds are affected.
  • Version 13.x builds are not affected because of architectural changes.
  • Unsupported product versions were not tested and should be treated as potentially vulnerable.

Veeam says version 13.x is not affected

Veeam says the flaw does not affect any Veeam Backup & Replication 13.x build because of architectural changes introduced in version 13. However, organizations still running version 12 should not wait for a larger upgrade project if they can install the fixed 12.3.2.4854 build now.

The official Veeam advisory credits Sina Kheirkhah of watchTowr for reporting the issue. It also warns customers that public patch disclosure gives attackers an opportunity to compare vulnerable and fixed builds.

Veeamโ€™s 12.3 release notes show that build 12.3.2.4854 includes the security fix and also adds Veeam Agent for Linux support updates. Admins can check their installed build number from the Veeam Backup & Replication Console under Help and About.

VersionStatusAction
12.3.2.4465 and earlier version 12 buildsAffectedUpdate to 12.3.2.4854
12.3.2.4854FixedDeploy after normal testing
13.xNot affected by this flawKeep current with regular security updates
Unsupported versionsNot formally testedTreat as vulnerable and upgrade

Why backup servers need urgent protection

Backup platforms are high-value targets during ransomware attacks. Attackers often try to steal backups, delete restore points, disable recovery tools, or use backup infrastructure to move deeper into a network.

The risk is not theoretical. The CISA Known Exploited Vulnerabilities catalog lists older Veeam Backup & Replication flaws, including CVE-2024-40711 and CVE-2023-27532, that have been exploited in real attacks.

BleepingComputerโ€™s report also notes that ransomware operators have repeatedly targeted Veeam backup servers because compromising them can help block restoration and increase pressure on victims.

What administrators should do now

Administrators should first identify every Veeam Backup & Replication server running version 12. Then they should confirm whether the server is domain-joined and whether it runs build 12.3.2.4465 or an earlier version 12 build.

Organizations should upgrade affected systems to build 12.3.2.4854 as soon as testing allows. If immediate patching is not possible, teams should restrict access to the backup server, monitor authentication activity, and limit which domain users can reach Veeam services over the network.

  • Install Veeam Backup & Replication 12.3.2.4854 on affected version 12 deployments.
  • Check whether the Veeam Backup Server is joined to a production domain.
  • Review domain user access to backup infrastructure.
  • Restrict network access to Veeam services from ordinary workstations.
  • Monitor for unusual logins, service activity, privilege escalation, and lateral movement.
  • Review backup server placement against the workgroup or domain guidance.
  • Check older Veeam exposure history through the CISA KEV catalog.

CVE-2026-44963 should receive high priority in enterprise patch queues because it affects a system attackers often seek during ransomware operations. The safest response is to patch affected Veeam 12 deployments, reduce domain exposure, and treat backup infrastructure as a privileged security boundary.

FAQ

What is CVE-2026-44963?

CVE-2026-44963 is a critical Veeam Backup & Replication vulnerability that can allow remote code execution on a backup server by an authenticated domain user.

Which Veeam versions are affected by CVE-2026-44963?

The vulnerability affects Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds. Veeam says version 13.x builds are not affected by this specific flaw.

Does CVE-2026-44963 affect every Veeam backup server?

No. Veeam says the vulnerability only affects domain-joined backup servers. Servers not joined to an Active Directory domain are not affected by this specific issue.

What version fixes CVE-2026-44963?

Veeam fixed CVE-2026-44963 in Veeam Backup & Replication 12.3.2.4854. Affected version 12 deployments should upgrade to that build or later.

Why are Veeam vulnerabilities serious for ransomware defense?

Backup servers can hold access to critical data and recovery systems. If attackers compromise them, they may delete backups, steal data, or make recovery from ransomware harder.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages