
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44963 is a critical remote code execution (RCE) vulnerability in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server. It affects Veeam Backup & Replication versions prior to 12.3.2 and was published on June 9, 2026, with a patch released on June 10, 2026. The vulnerability was reported via HackerOne and is classified as Critical with a CVSS v4.0 base score of 9.4 (GitHub Advisory, Veeam KB4869).
The root cause is improper deserialization of untrusted data (CWE-502), mapped to CAPEC-586 (Object Injection). An attacker with low-privilege domain user credentials can send a crafted network request to the Backup Server that triggers unsafe deserialization, leading to arbitrary code execution without requiring user interaction or special attack conditions. The attack is network-accessible, requires no elevated privileges beyond domain authentication, and has low attack complexity, making it straightforward to exploit once credentials are obtained (GitHub Advisory, Veeam KB4869).
Successful exploitation grants an attacker full remote code execution on the Veeam Backup Server, with high impact to confidentiality, integrity, and availability of both the vulnerable system and subsequent systems. Because backup servers typically hold credentials, backup data, and network access to a broad range of infrastructure, compromise can enable lateral movement, ransomware deployment, data exfiltration, and destruction of backup data — eliminating recovery options for the organization. The Feedly executive summary specifically notes the risk of ransomware actors leveraging this flaw, consistent with historical targeting of Veeam by groups such as Akira (GitHub Advisory, BleepingComputer).
As of the time of reporting, there is no confirmed in-the-wild exploitation and no functional public proof-of-concept exploit. A GitHub repository (HORKimhab/CVE-2026-44963) was identified but assessed as non-exploitable — containing only template files with no actual exploit code. A second repository (SentinelXofficial/CVE-2026-44963) also appeared. The CVE is not currently listed in the CISA KEV catalog. The EPSS score is approximately 0.887% (55th percentile), indicating moderate predicted exploitation probability. Qualys has released a detection plugin (ID 320202) and Tenable has a Nessus plugin (ID 320202) for scanning (GitHub Advisory, Feedly).
cmd.exe, powershell.exe, wscript.exe, mshta.exe) with no corresponding scheduled job or administrative action.Veeam has released a patch in version 12.3.2 (build 4854) of Veeam Backup & Replication, published June 10, 2026. Organizations should upgrade to version 12.3.2 or later immediately. As interim mitigations, restrict domain user access to the Backup Server to only accounts that operationally require it, enforce network segmentation to limit which hosts can reach Veeam management ports, and monitor Backup Server activity for anomalous remote code execution indicators. The Belgium CCB and Ireland NCSC have both issued advisories urging immediate patching (Veeam KB4869, GitHub Advisory).
The vulnerability received broad coverage across the security community shortly after disclosure. BleepingComputer, The Hacker News, Security Affairs, and GBHackers all published articles highlighting the risk to enterprise backup infrastructure and the potential for ransomware exploitation (BleepingComputer, The Hacker News, Security Affairs). National CERTs including Belgium's CCB, Ireland's NCSC, Austria's CERT.at, and Thailand's ThaiCERT issued advisories urging immediate patching. Community discussion on Reddit (r/Veeam, r/pwnhub) and Mastodon/Infosec.exchange reflected concern about the low privilege bar required for exploitation. Multiple outlets drew parallels to prior Veeam vulnerabilities that were weaponized by ransomware groups such as Akira.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."