Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilityidentity-authentication-vulnerabilityransomware-group-operation

Critical RCE in Veeam Backup & Replication Exposes Domain-Joined Servers

Updated 14d agoFirst seen Jun 9, 20268 sources

Veeam has released fixes for a critical remote code execution flaw in Veeam Backup & Replication, tracked as CVE-2026-44963, affecting version 12.3.2.4465 and earlier 12.x builds on Windows domain-joined servers. The vulnerability was reported by WatchTowr researcher Sina Kheirkhah and allows any authenticated low-privileged domain user to execute arbitrary code on the backup server, giving attackers a path to compromise backup infrastructure in Active Directory environments. Veeam says version 13.x is not affected because of architectural changes, and the issue is resolved in Veeam Backup & Replication 12.3.2.4854.

The flaw has not been publicly reported as exploited, but Veeam warned that attackers often reverse-engineer patches quickly to target unpatched systems. The issue carries a CVSS v4 score of 9.4 and is especially serious because backup servers are frequent ransomware targets: compromising them can enable data theft, lateral movement, privilege escalation, and destruction of backups. Reporting on the disclosure also pointed to earlier Veeam-focused attacks, including abuse of CVE-2024-40711 by Akira, Fog, and Frag, underscoring the need for organizations to patch immediately, review domain-joined deployments, restrict unnecessary domain user access, and closely monitor backup infrastructure.

Share:
Critical RCE in Veeam Backup & Replication Exposes Domain-Joined Servers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jun 9, 202617d ago

Veeam releases fix for CVE-2026-44963 in version 12.3.2.4854

Veeam released security updates addressing CVE-2026-44963 in Veeam Backup & Replication 12.3.2.4854. The company said version 13.x is not affected because of architectural changes.

New Veeam vulnerability exposes backup servers to RCE attacks

WatchTowr researcher reports Veeam Backup & Replication RCE flaw

Sina Kheirkhah of WatchTowr identified and reported a critical remote code execution vulnerability in Veeam Backup & Replication, tracked as CVE-2026-44963. The flaw affects domain-joined Veeam Backup & Replication version 12 deployments through 12.3.2.4465 and earlier 12.x builds.

New Veeam vulnerability exposes backup servers to RCE attacks
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Threat actors
5 linked
Affected products
1 linked
Veeam Backup & Replication
Organizations
5 linked
Veeam SoftwareWatchTowrBleepingComputerSophosSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.