Remote Code Execution Vulnerability in Veeam Backup Server
CVE-2026-44963
Key Information:
- Vendor
Veeam
- Status
- Vendor
- CVE Published:
- 9 June 2026
Badges
What is CVE-2026-44963?
CVE-2026-44963 is a critical vulnerability affecting the Veeam Backup Server used for data backup, recovery, and replication. This product plays a vital role in enterprise data management, ensuring that businesses can efficiently recover from data loss incidents. The vulnerability allows authenticated domain users to execute arbitrary remote code on the Backup Server, risking the integrity and availability of backup data. This situation presents a unique threat, as attackers can exploit this loophole to manipulate backups, potentially leading to concealed data theft, disruptions in recovery processes, or even complete system compromise.
Potential impact of CVE-2026-44963
-
Data Integrity Compromise: Attackers could alter backup data, making it unreliable for recovery purposes. This could lead to businesses restoring corrupted data, resulting in significant operational disruption and reputational damage.
-
Unauthorized System Control: The remote code execution capability means that malicious actors could gain full control over the Veeam Backup Server, allowing them to deploy additional malware, exfiltrate sensitive information, or pivot to other systems within the network.
-
Increased Vulnerability to Ransomware Attacks: With the ability to manipulate and control backup systems, such vulnerabilities create a fertile ground for ransomware groups. They could target the backup infrastructure to ensure that organizations cannot recover from an attack, leading to higher likelihood of ransom payments and extended downtime.
Affected Version(s)
Backup and Replication 0 < 12.3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
Veeam fixes CVE-2026-44963 RCE in 12 builds, blocking authenticated domain users from attacking backup servers.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
- π°
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved