Junglewise Threat Intelligence

CVE-2026-44963: Veeam Backup & Replication RCE via untrusted deserialization

CVE-2026-44963 · Severity: info · CVSS 9.4 · Published 2026-06-09

Executive brief

Veeam Backup & Replication is a platform used by organizations to back up, restore, and replicate data across their infrastructure. A security vulnerability has been identified that allows a person with basic domain user credentials to take full control of the backup server. This could lead to the theft or destruction of backup data, potentially crippling an organization's ability to recover from a ransomware attack or system failure.

Technical details

A remote code execution (RCE) vulnerability exists in Veeam Backup & Replication due to the insecure deserialization of untrusted data (CWE-502). The flaw allows an attacker who is authenticated as a domain user to execute arbitrary code on the Backup Server, provided the server is domain-joined. The vulnerability affects all version 12 builds prior to 12.3.2.4854. Version 13.x is not affected due to architectural changes. Users are advised to update to build 12.3.2.4854 or migrate to version 13 to mitigate the risk.

Affected products

  • Veeam Backup & Replication 12.x builds prior to 12.3.2.4854

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: patched: Fixed in version 12.3.2.4854
  • 2026-06-09: advisory

References

Related threats