Critical Veeam Vulnerability Allows RCE Attacks on Backup Servers
ID: ee581dc1-3d30-5281-bd25-06e4bc8d11e3
STIX ID: report--ee581dc1-3d30-5281-bd25-06e4bc8d11e3
Feed Name: cybersecurityNews.com
A critical RCE in Veeam Backup & Replication (CVE-2026-44963, CVSS v4 9.4) enables any authenticated domain user to execute arbitrary code on domain-joined backup servers for versions 12 through 12.3.2.4465. Veeam released a fix in 12.3.2.4854 (June 9, 2026); organizations are advised to patch immediately, audit whether backup servers are domain-joined, consider workgroup configurations per best practices, and review domain user access to reduce risk of exploitation and ransomware targeting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
