Remote Code Execution Vulnerability in Veeam Backup Server
CVE-2026-44963

9.4CRITICAL

Key Information:

Vendor

Veeam

Vendor
CVE Published:
9 June 2026

Badges

πŸ“ˆ Score: 738πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-44963?

CVE-2026-44963 is a critical vulnerability affecting the Veeam Backup Server used for data backup, recovery, and replication. This product plays a vital role in enterprise data management, ensuring that businesses can efficiently recover from data loss incidents. The vulnerability allows authenticated domain users to execute arbitrary remote code on the Backup Server, risking the integrity and availability of backup data. This situation presents a unique threat, as attackers can exploit this loophole to manipulate backups, potentially leading to concealed data theft, disruptions in recovery processes, or even complete system compromise.

Potential impact of CVE-2026-44963

  1. Data Integrity Compromise: Attackers could alter backup data, making it unreliable for recovery purposes. This could lead to businesses restoring corrupted data, resulting in significant operational disruption and reputational damage.

  2. Unauthorized System Control: The remote code execution capability means that malicious actors could gain full control over the Veeam Backup Server, allowing them to deploy additional malware, exfiltrate sensitive information, or pivot to other systems within the network.

  3. Increased Vulnerability to Ransomware Attacks: With the ability to manipulate and control backup systems, such vulnerabilities create a fertile ground for ransomware groups. They could target the backup infrastructure to ensure that organizations cannot recover from an attack, leading to higher likelihood of ransom payments and extended downtime.

Affected Version(s)

Backup and Replication 0 < 12.3.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code

Veeam fixes CVE-2026-44963 RCE in 12 builds, blocking authenticated domain users from attacking backup servers.

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.