Veeam Backup & Replication Remote Code Execution Vulnerability

CVE-2026-44963 Remote Code Execution Backup Infrastructure Ransomware Risk
Overview
A critical vulnerability in Veeam Backup & Replication allows authenticated low-privileged domain users to execute arbitrary code remotely on vulnerable backup servers. Since backup infrastructure is highly sensitive and often connected to core enterprise systems, successful exploitation may lead to full infrastructure compromise and ransomware deployment. The flaw affects domain-joined servers running version 12.3.2.4465 and earlier, and has been patched in version 12.3.2.4854.
Technical Specifications
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-44963 |
| Vulnerability Type | Remote Code Execution |
| CVSS Score | Critical |
| Attack Vector | Network |
| Authentication | Low-privileged domain user (Active Directory account required) |
| Complexity | Low |
| User Interaction | Not Required |
| Affected Versions | Veeam Backup & Replication 12.3.2.4465 and earlier (domain-joined) |
| Fixed Version | 12.3.2.4854 |
| Unaffected | Veeam Backup & Replication 13.x (architectural changes) |
Affected Products
- Veeam Backup & Replication 12.3.2.4465 and earlier
- Domain-joined Veeam backup servers with Active Directory integration
- Enterprise environments where backup servers are accessible to domain users
Attack Scenario
- Attacker compromises a low-privileged employee domain account via phishing, credential theft, or another intrusion method.
- Using the compromised AD account, the attacker targets the vulnerable Veeam backup server.
- Attacker exploits CVE-2026-44963 to achieve remote code execution on the backup server.
- Attacker moves laterally within the environment using backup server access.
- Attacker disables or deletes backups to prevent recovery, steals credentials, and deploys ransomware across the environment.
Impact
- Full compromise of backup infrastructure with remote code execution capabilities
- Deletion or encryption of backups, eliminating disaster recovery options
- Ransomware deployment across the enterprise environment
- Credential theft from the backup server and connected systems
- Access to sensitive backup data including databases, files, and system images
- Exposure of Tier-0 asset configurations and enterprise infrastructure details
- Operational disruption and data loss from backup destruction
- Inability to recover critical systems following a ransomware attack
- Extended downtime due to loss of backup and recovery capabilities
Mitigations
Immediate Actions
- Upgrade immediately to Veeam Backup & Replication 12.3.2.4854 or later
- Restrict domain user access to backup servers and review service account permissions
- Segment backup servers from production networks
Short-term Measures
- Enable MFA for all administrative and backup infrastructure accounts
- Use immutable and offline backups to protect against deletion or encryption
- Limit Active Directory accounts with access to backup infrastructure
Monitoring & Detection
- Monitor for suspicious authentication attempts targeting backup servers
- Alert on anomalous PowerShell activity, backup deletion events, and lateral movement
- Deploy EDR monitoring on backup infrastructure
Long-term Solutions
- Treat backup servers as Tier-0 assets with hardened access controls
- Enforce network segmentation and zero-trust policies around backup infrastructure
- Maintain offline, air-gapped backup copies to ensure recoverability
Resources
Open-Source Reporting
Last Updated: June 10, 2026