CVE-2026-44963
Veeam Backup & Replication vulnerability analysis and mitigation

Overview

CVE-2026-44963 is a critical remote code execution (RCE) vulnerability in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server. It affects Veeam Backup & Replication versions prior to 12.3.2 and was published on June 9, 2026, with a patch released on June 10, 2026. The vulnerability was reported via HackerOne and is classified as Critical with a CVSS v4.0 base score of 9.4 (GitHub Advisory, Veeam KB4869).

Technical details

The root cause is improper deserialization of untrusted data (CWE-502), mapped to CAPEC-586 (Object Injection). An attacker with low-privilege domain user credentials can send a crafted network request to the Backup Server that triggers unsafe deserialization, leading to arbitrary code execution without requiring user interaction or special attack conditions. The attack is network-accessible, requires no elevated privileges beyond domain authentication, and has low attack complexity, making it straightforward to exploit once credentials are obtained (GitHub Advisory, Veeam KB4869).

Impact

Successful exploitation grants an attacker full remote code execution on the Veeam Backup Server, with high impact to confidentiality, integrity, and availability of both the vulnerable system and subsequent systems. Because backup servers typically hold credentials, backup data, and network access to a broad range of infrastructure, compromise can enable lateral movement, ransomware deployment, data exfiltration, and destruction of backup data — eliminating recovery options for the organization. The Feedly executive summary specifically notes the risk of ransomware actors leveraging this flaw, consistent with historical targeting of Veeam by groups such as Akira (GitHub Advisory, BleepingComputer).

Exploitability

As of the time of reporting, there is no confirmed in-the-wild exploitation and no functional public proof-of-concept exploit. A GitHub repository (HORKimhab/CVE-2026-44963) was identified but assessed as non-exploitable — containing only template files with no actual exploit code. A second repository (SentinelXofficial/CVE-2026-44963) also appeared. The CVE is not currently listed in the CISA KEV catalog. The EPSS score is approximately 0.887% (55th percentile), indicating moderate predicted exploitation probability. Qualys has released a detection plugin (ID 320202) and Tenable has a Nessus plugin (ID 320202) for scanning (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Veeam Backup & Replication servers running versions prior to 12.3.2 using network scanners (e.g., Nmap, Shodan) or internal asset inventories.
  2. Obtain domain credentials: Acquire any valid domain user account credentials — these can be low-privilege accounts, obtained via phishing, credential stuffing, or prior compromise of a domain-joined endpoint.
  3. Identify the vulnerable service endpoint: Locate the Veeam Backup Server's management service port (typically TCP 9392 or related Veeam service ports) that handles authenticated requests.
  4. Craft a malicious deserialization payload: Construct a serialized object payload (e.g., using tools like ysoserial.net for .NET deserialization gadget chains) targeting the Veeam Backup Server's deserialization routine.
  5. Send the payload: Authenticate to the Veeam service using the domain credentials and submit the crafted payload to the vulnerable endpoint over the network.
  6. Achieve code execution: The server deserializes the malicious object, triggering execution of attacker-controlled commands as the Veeam service account (typically with high privileges), enabling reverse shell establishment, credential harvesting, or ransomware deployment (GitHub Advisory, BleepingComputer).

Indicators of compromise

  • Network: Unexpected inbound connections to Veeam Backup Server management ports (e.g., TCP 9392, 9401) from unusual source IPs or non-administrative hosts; outbound connections from the Veeam server process to unknown external IPs.
  • Process: Unusual child processes spawned by the Veeam Backup Service (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) with no corresponding scheduled job or administrative action.
  • Logs: Veeam application logs showing deserialization errors or unexpected object instantiation; Windows Event Logs (Security) showing new process creation (Event ID 4688) under the Veeam service account context.
  • File System: New or modified executables, scripts, or scheduled tasks in Veeam installation directories or temp folders; presence of web shells or reverse shell binaries dropped by the Veeam service account.
  • Registry: New run keys or scheduled tasks created under the Veeam service account's context that were not provisioned by administrators.

Mitigation and workarounds

Veeam has released a patch in version 12.3.2 (build 4854) of Veeam Backup & Replication, published June 10, 2026. Organizations should upgrade to version 12.3.2 or later immediately. As interim mitigations, restrict domain user access to the Backup Server to only accounts that operationally require it, enforce network segmentation to limit which hosts can reach Veeam management ports, and monitor Backup Server activity for anomalous remote code execution indicators. The Belgium CCB and Ireland NCSC have both issued advisories urging immediate patching (Veeam KB4869, GitHub Advisory).

Community reactions

The vulnerability received broad coverage across the security community shortly after disclosure. BleepingComputer, The Hacker News, Security Affairs, and GBHackers all published articles highlighting the risk to enterprise backup infrastructure and the potential for ransomware exploitation (BleepingComputer, The Hacker News, Security Affairs). National CERTs including Belgium's CCB, Ireland's NCSC, Austria's CERT.at, and Thailand's ThaiCERT issued advisories urging immediate patching. Community discussion on Reddit (r/Veeam, r/pwnhub) and Mastodon/Infosec.exchange reflected concern about the low privilege bar required for exploitation. Multiple outlets drew parallels to prior Veeam vulnerabilities that were weaponized by ransomware groups such as Akira.

Additional resources


SourceThis report was generated using AI

Related Veeam Backup & Replication vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21708CRITICAL9.9
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMar 12, 2026
CVE-2026-44963CRITICAL9.4
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesJun 09, 2026
CVE-2026-32997HIGH8.6
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-32996HIGH7.3
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesMay 28, 2026
CVE-2026-21709MEDIUM6.7
  • Veeam Backup & Replication logoVeeam Backup & Replication
  • cpe:2.3:a:veeam:veeam_backup_\&_replication
NoYesApr 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management