XOOMAR
Backup server under cyberattack with cracked shield, locks, and dark data streams
CybersecurityJune 9, 2026· 5 min read· By XOOMAR Insights Team

Low-Privilege Users Can Hijack Veeam Backup Servers via RCE

Share
Updated on June 9, 2026

Veeam Backup & Replication servers joined to a Windows domain are exposed to a newly patched critical RCE flaw that a low-privileged authenticated domain user can exploit against affected installations.

XOOMAR Intelligence

Analyst Take

59/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness99Source Trust88Factual Grounding94Signal Cluster20

The vulnerability, tracked as CVE-2026-44963, affects Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds, and was fixed in version 12.3.2.4854, according to BleepingComputer. The bug was reported by WatchTowr security researcher Sina Kheirkhah.

Domain-joined Veeam servers carry the sharpest risk

Veeam says the flaw can let an authenticated domain user execute code remotely on the backup server. That is the dangerous part. Backup servers often sit close to the systems companies most need during a breach.

“A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user,” Veeam said in its advisory.

The exposure is not universal across every deployment. The source material says the flaw only affects Veeam Backup & Replication installations that are joined to a domain. It also does not affect version 13.x builds because of architectural changes introduced in version 13.

So the first question for administrators is blunt: is the VBR server joined to a Windows domain, and is it running an affected version 12 build?

Veeam has long advised against configurations that increase backup server exposure, but BleepingComputer reports that many companies have still joined their Veeam servers to a Windows domain. That matters because the exploit condition is not “internet-exposed attacker with no access.” It is an authenticated domain user with low privileges.

That still leaves real risk. In a compromised Windows environment, low-privilege domain access is often not the end of an intrusion. It is the starting point.

Affected and fixed versions:

Product Affected builds Fixed build Not affected
Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds 12.3.2.4854 13.x builds

Veeam also warned that patch disclosure can start a race. Once attackers can compare vulnerable and fixed code, exploit development becomes more practical. That same dynamic has driven urgent patch cycles across other software categories, as XOOMAR has covered in Fifth Chrome Zero-Day Forces an Urgent Google Patch and Chrome Zero-Day Forces Google Into a 74-Bug Patch Race.


Ransomware crews already know why Veeam matters

There are no reports of active exploitation of CVE-2026-44963, according to the supplied source material. That is the good news. The bad news is the target class.

BleepingComputer reports that ransomware gangs have previously said they target Veeam backup servers because those systems can help them steal sensitive data, move through breached networks, and block restoration by deleting backups.

That makes this patch different from a routine enterprise software update. If an attacker can execute code on a backup server, the blast radius can reach beyond one machine. The backup environment can become a control point over recovery itself.

Four Veeam Backup & Replication vulnerabilities have been flagged by CISA in recent years as actively exploited in attacks, and BleepingComputer says all were abused by ransomware gangs. One example is CVE-2024-40711, a critical VBR RCE flaw that Sophos X-Ops reported in November 2024 had been weaponized by several ransomware operations, including Akira, Fog, and Frag.

Other groups have also been linked to attacks targeting VBR flaws. The source names FIN7, which often collaborated with Maze, Egregor, Conti, REvil, and BlackBasta, as well as the Cuba ransomware gang.

The scale raises the stakes. Veeam products are used by more than 550,000 customers worldwide, including 82% of Fortune 500 companies and 74% of Global 2,000 firms.

The practical question is not whether every exposed Veeam server will be attacked. It is whether defenders can patch faster than attackers can reverse-engineer the update and find reachable, domain-joined deployments.

Security teams should patch version 12 and challenge domain access

Administrators running affected Veeam Backup & Replication 12 builds should move to 12.3.2.4854 as a priority. Teams already on 13.x are outside the scope of this specific flaw, based on Veeam’s statement cited by BleepingComputer.

A useful first pass is narrow and fast:

  • Version check: Confirm whether any VBR server is running 12.3.2.4465 or an earlier version 12 build.
  • Domain status: Identify which backup servers are joined to a Windows domain.
  • Access review: Check which domain users and groups can authenticate to systems that host or manage backup infrastructure.
  • Patch coverage: Verify that all production and non-production VBR servers are updated, not just the primary system administrators remember first.

What should security teams review first after patching?

Start with the condition that makes this bug exploitable: authenticated domain access to a domain-joined backup server. XOOMAR analysis: because the flaw requires a domain user and affects domain-joined deployments, the most relevant immediate checks are authentication paths into backup servers, privileged access around VBR, and whether backup infrastructure is segmented from broader domain activity. The source does not report active exploitation, so defenders should avoid assuming compromise without evidence.

Veeam’s own warning is the near-term watch item. Patch releases can become exploit roadmaps for attackers hunting unpatched systems.

If public exploit code appears, or if ransomware crews begin using CVE-2026-44963 in intrusions, domain-joined VBR 12 servers that missed the update will move from “urgent patch” to “likely target.” For now, the cleanest move is simple: update Veeam, reduce domain exposure where possible, and treat backup servers as ransomware targets before attackers do.

Impact Analysis

  • Backup servers are high-value targets because they are critical to recovery during ransomware and breach response.
  • The flaw can be exploited by a low-privileged authenticated domain user, making it dangerous after initial network compromise.
  • Organizations running domain-joined Veeam 12.x servers should verify exposure and apply the fixed version quickly.

Veeam Backup & Replication Exposure by Version

Version/ConfigurationStatusRisk
Veeam Backup & Replication 12.3.2.4465 and earlier 12.x builds joined to a Windows domainAffectedAuthenticated low-privileged domain users may exploit RCE on the backup server
Veeam Backup & Replication 12.3.2.4854FixedPatch addresses CVE-2026-44963
Veeam Backup & Replication 13.xNot affectedArchitectural changes in version 13 prevent exposure
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Conceptual image showing the words 'Ethical Hacking' on a textured abstract background.Cybersecurity

Critical Gitea Bug Hijacks Systems for Crypto Mining

A critical Gitea vulnerability is under active attack, letting hackers hijack servers for cryptocurrency mining, confirmed by CISA's urgent patch order.

Aug 26, 20267 min
Close-up of a smartphone displaying a bank alert notification on a wooden table.Cybersecurity

Citrix Patch Fail Forces U.S. 72-Hour Crisis Ultimatum

A previously patched Citrix NetScaler flaw is being actively exploited, prompting a formal U.S. government emergency order giving all federal agencies just 72 h

Aug 27, 20268 min
Text 'Cyber Attack' on textured dark paper highlights digital security threat concept.Cybersecurity

Hackers Mass-Exploit Patched SharePoint Flaw After Public PoC

Attackers are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) using public proof-of-concept code, targeting organizations tha

Aug 13, 20265 min
A hacker in a black hoodie using a tablet displaying a skull, surrounded by chalk symbols and 'Hacker Attack' text.Cybersecurity

AI Wrote a Zoom Hack in Under 20 Prompts

Researchers weaponized a critical Zoom flaw using fewer than 20 AI prompts, collapsing the barrier to sophisticated cyberattacks and turning screen-sharing into

Aug 11, 20265 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Feds Set Deadline as Hackers Hit AI Tool, Web Server Code

The US government has issued a mandatory remediation deadline after confirming attackers are actively exploiting critical bugs in Langflow, Apache Tomcat, and N

Aug 6, 20265 min
An abstract, cinematic visualization of global economic trends, showing rising growth metrics under the scrutiny of inflationary pressures.Global Trends

Fed Ignores Jobs Report, Zeroes in on Inflation Battle

Despite a robust rebound in U.S. hiring, the Federal Reserve is solely focused on inflation, signaling a pivotal shift in its monetary policy priorities.

Sep 7, 20267 min
A futuristic tech event hall with glowing podiums and holographic displays, set for a major conference announcement.Technology

TechCrunch's Side Event Pitch Closes in 24 Hours

The deadline to apply to host a sponsored side event at TechCrunch Disrupt 2026 is tonight at midnight PT, offering approved organizers massive promotional acce

Sep 7, 20265 min
Modern bridge connecting Russia and North Korea at dusk, symbolizing new strategic corridor.Global Trends

Kim’s New Bridge Fuels Putin’s Ukraine War Machine

A new road bridge linking Russia and North Korea is not for trade, but a secure corridor to move troops, weapons and tech, directly supplying Putin's war in Ukr

Sep 7, 20266 min
Silver bar and trading chart depicting a bearish Head & Shoulders pattern in financial markets.Trading

Silver Rejected at $68, Risks $61 Tumble

After a sudden reversal rejected its rally at $68, silver is forming a bearish Head & Shoulders pattern, risking a significant drop toward $61.

Sep 7, 20268 min
Futuristic security operations center with holographic threat maps and neural networks symbolizing digital risk assessment.Technology

Armed Attacker Lunges at Ohio Governor Candidate at Fair

An armed assailant attacked Democratic gubernatorial candidate Amy Acton at an Ohio county fair, highlighting the rising threat of political violence in everyda

Sep 7, 20265 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.