
Yesterday, Veeam addressed a critical vulnerability in its Backup & Replication v12 product, that allows adversaries to execute arbitrary code on the Backup Server… but only when the host is domain-joined.
About Veeam Backup & Replication
Veeam Backup & Replication (VBR) is a comprehensive data protection and disaster recovery solution designed for virtual, physical, and cloud-based workloads. It provides fast, secure backup, replication, and restoration for platforms like VMware, Hyper-V, AWS, Azure, and Google Cloud. Key features include image-level backups, instant VM recovery, ransomware protection via immutable storage, and built-in WAN acceleration.
Veeam's products are used by over 550,000 organizations worldwide, including 82% of Fortune 500 companies and 74% of Global 2,000 firms.
About the vulnerability
Veeam Backup & Replication v12.3.2.4854, released on June 9th, 2026, addresses a critical vulnerability.
The vulnerability, known as CVE-2026-44963, and accompanied by a CVSS v4 score of 9.4 on a scale of 1 to 10, allows remote code execution (RCE) on the Backup Server by an authenticated domain user.
The vulnerability was reponsibly disclosed to Veeam by Sina Kheirkhah of WatchTowr.
Is my Backup Server vulnerable?
A Backup Server is only vulnerable if both following conditions are met:
- The Backup Server runs one of the following versions:
- v12.3.2.4465
- v12.3.2.4165
- v12.3.2.3617
- v12.3.1.1139
- v12.3.0.310
- v12.2.x
- v12.1.x
- v12.0.x
- The Backup Server is joined to Active Directory
Call to Action
The above vulnerability is addressed by upgrading Veeam Backup & Replication v12 to v12.3.2.4854, or up. Please update your Backup Servers.
Veeam has long recommended to no longer join Backup Servers to Active Directory. If this recommendation was missed, reimplementing Veeam Backup & Replication on non-domain-joined hosts may be a worthwhile item on your system administration team's backlog.






Login