logo

New Veeam Vulnerability Exposes Backup Servers to RCE Attacks

ID: d43cdeac-636c-5ea6-9a73-812ac4bc551e

STIX ID: report--d43cdeac-636c-5ea6-9a73-812ac4bc551e

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-09

Date Updated: 2026-06-11

...
...

Veeam Backup & Replication has a critical RCE vulnerability (CVE-2026-44963, CVSS 9.4) that allows authenticated domain users to execute code as SYSTEM on domain-joined backup servers, creating a severe ransomware-enablement risk by enabling deletion or encryption of backups; organizations should apply Veeam's patches immediately, isolate backup servers if necessary, audit service account permissions, and implement immutability and air-gapped backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.