A critical vulnerability was resolved in Veeam Backup & Replication v12.3.2.4854

Reading Time: 2 minutes

Veeam Backup & Replication

Yesterday, Veeam addressed a critical vulnerability in its Backup & Replication v12 product, that allows adversaries to execute arbitrary code on the Backup Server… but only when the host is domain-joined.

 

About Veeam Backup & Replication

Veeam Backup & Replication (VBR) is a comprehensive data protection and disaster recovery solution designed for virtual, physical, and cloud-based workloads. It provides fast, secure backup, replication, and restoration for platforms like VMware, Hyper-V, AWS, Azure, and Google Cloud. Key features include image-level backups, instant VM recovery, ransomware protection via immutable storage, and built-in WAN acceleration.

Veeam's products are used by over 550,000 organizations worldwide, including 82% of Fortune 500 companies and 74% of Global 2,000 firms.

 

About the vulnerability

Veeam Backup & Replication v12.3.2.4854, released on June 9th, 2026, addresses a critical vulnerability.

The vulnerability, known as CVE-2026-44963, and accompanied by a CVSS v4 score of 9.4 on a scale of 1 to 10, allows remote code execution (RCE) on the Backup Server by an authenticated domain user.

The vulnerability was reponsibly disclosed to Veeam by Sina Kheirkhah of WatchTowr.

 

Is my Backup Server vulnerable?

A Backup Server is only vulnerable if both following conditions are met:

  • The Backup Server runs one of the following versions:
    • v12.3.2.4465
    • v12.3.2.4165
    • v12.3.2.3617
    • v12.3.1.1139
    • v12.3.0.310
    • v12.2.x
    • v12.1.x
    • v12.0.x
  • The Backup Server is joined to Active Directory

 

Call to Action

The above vulnerability is addressed by upgrading Veeam Backup & Replication v12 to v12.3.2.4854, or up. Please update your Backup Servers.

Veeam has long recommended to no longer join Backup Servers to Active Directory. If this recommendation was missed, reimplementing Veeam Backup & Replication on non-domain-joined hosts may be a worthwhile item on your system administration team's backlog.

leave your comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.