Veeam has released fixes for a critical remote code execution flaw in Veeam Backup & Replication, tracked as CVE-2026-44963, affecting version 12.3.2.4465 and earlier 12.x builds on Windows domain-joined servers. The vulnerability was reported by WatchTowr researcher Sina Kheirkhah and allows any authenticated low-privileged domain user to execute arbitrary code on the backup server, giving attackers a path to compromise backup infrastructure in Active Directory environments. Veeam says version 13.x is not affected because of architectural changes, and the issue is resolved in Veeam Backup & Replication 12.3.2.4854.
The flaw has not been publicly reported as exploited, but Veeam warned that attackers often reverse-engineer patches quickly to target unpatched systems. The issue carries a CVSS v4 score of 9.4 and is especially serious because backup servers are frequent ransomware targets: compromising them can enable data theft, lateral movement, privilege escalation, and destruction of backups. Reporting on the disclosure also pointed to earlier Veeam-focused attacks, including abuse of CVE-2024-40711 by Akira, Fog, and Frag, underscoring the need for organizations to patch immediately, review domain-joined deployments, restrict unnecessary domain user access, and closely monitor backup infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Veeam released security updates addressing CVE-2026-44963 in Veeam Backup & Replication 12.3.2.4854. The company said version 13.x is not affected because of architectural changes.
Sina Kheirkhah of WatchTowr identified and reported a critical remote code execution vulnerability in Veeam Backup & Replication, tracked as CVE-2026-44963. The flaw affects domain-joined Veeam Backup & Replication version 12 deployments through 12.3.2.4465 and earlier 12.x builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceccb.belgium.be
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceveeam.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.