Veeam Patches Critical CVE-2026-44963 RCE In Backup Replication

Veeam has shipped patches for CVE-2026-44963, a CVSS 9.4 remote code execution flaw in Backup & Replication 12.x that lets authenticated domain users seize backup servers, with watchTowr credited for the find.

Veeam Patches Critical CVE-2026-44963 RCE In Backup Replication

Veeam Software has shipped emergency patches for CVE-2026-44963, a critical remote code execution flaw in Veeam Backup & Replication that carries a CVSS score of 9.4 and lets an authenticated domain user run arbitrary code on the backup server.

All version 12 builds in scope

The vulnerability affects Veeam Backup & Replication 12.3.2.4465 and every earlier build in the 12.x line. Veeam fixed the issue in 12.3.2.4854 and confirmed that the architectural rewrite behind 13.x makes that branch immune. "A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user," the company said in a Tuesday advisory, urging customers to upgrade immediately. Only domain-joined backup servers are exposed; workgroup deployments are unaffected.

watchTowr credit, ransomware risk

Veeam credited watchTowr researcher Sina Kheirkhah with the responsible disclosure. The vendor's patches arrive against a backdrop in which CISA has flagged four prior Veeam Backup & Replication flaws as actively exploited by ransomware crews, and after Veeam closed seven critical Backup & Replication flaws in March 2026 alone. Akira, Fog, Frag, Cuba and FIN7 are among the operations historically linked to attacks on Veeam infrastructure.

Enterprise server racks running data protection workloads in a modern data center

Backup servers remain a high-value target

Backup infrastructure is a top target because compromising it neutralises the only line of defence against ransomware encryption events. Veeam said attackers will likely attempt to reverse-engineer the patch and target unpatched deployments. With Veeam used by more than 550,000 customers worldwide, including 82% of Fortune 500 firms, defenders are advised to isolate Veeam from production Active Directory where possible, monitor authentication anomalies and stage the upgrade to 12.3.2.4854 ahead of the long-term move to 13.x.

The advisory follows Microsoft's record June 2026 Patch Tuesday and CISA's addition of the BerriAI LiteLLM flaw to the KEV catalogue.

Reporting based on coverage from Veeam Security Advisory, BleepingComputer and The Hacker News.

Category: Cyber Security

Tags: Medical Devices Robotics AI venture capital Security Cybersecurity

Related Articles