XOOMAR
Backup server under cyberattack with cracked shield, locks, and dark data streams
CybersecurityJune 9, 2026· 5 min read· By XOOMAR Insights Team

Low-Privilege Users Can Hijack Veeam Backup Servers via RCE

Share
Updated on June 9, 2026

Veeam Backup & Replication servers joined to a Windows domain are exposed to a newly patched critical RCE flaw that a low-privileged authenticated domain user can exploit against affected installations.

XOOMAR Intelligence

Analyst Take

59/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness99Source Trust88Factual Grounding94Signal Cluster20

The vulnerability, tracked as CVE-2026-44963, affects Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds, and was fixed in version 12.3.2.4854, according to BleepingComputer. The bug was reported by WatchTowr security researcher Sina Kheirkhah.

Domain-joined Veeam servers carry the sharpest risk

Veeam says the flaw can let an authenticated domain user execute code remotely on the backup server. That is the dangerous part. Backup servers often sit close to the systems companies most need during a breach.

“A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user,” Veeam said in its advisory.

The exposure is not universal across every deployment. The source material says the flaw only affects Veeam Backup & Replication installations that are joined to a domain. It also does not affect version 13.x builds because of architectural changes introduced in version 13.

So the first question for administrators is blunt: is the VBR server joined to a Windows domain, and is it running an affected version 12 build?

Veeam has long advised against configurations that increase backup server exposure, but BleepingComputer reports that many companies have still joined their Veeam servers to a Windows domain. That matters because the exploit condition is not “internet-exposed attacker with no access.” It is an authenticated domain user with low privileges.

That still leaves real risk. In a compromised Windows environment, low-privilege domain access is often not the end of an intrusion. It is the starting point.

Affected and fixed versions:

Product Affected builds Fixed build Not affected
Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds 12.3.2.4854 13.x builds

Veeam also warned that patch disclosure can start a race. Once attackers can compare vulnerable and fixed code, exploit development becomes more practical. That same dynamic has driven urgent patch cycles across other software categories, as XOOMAR has covered in Fifth Chrome Zero-Day Forces an Urgent Google Patch and Chrome Zero-Day Forces Google Into a 74-Bug Patch Race.


Ransomware crews already know why Veeam matters

There are no reports of active exploitation of CVE-2026-44963, according to the supplied source material. That is the good news. The bad news is the target class.

BleepingComputer reports that ransomware gangs have previously said they target Veeam backup servers because those systems can help them steal sensitive data, move through breached networks, and block restoration by deleting backups.

That makes this patch different from a routine enterprise software update. If an attacker can execute code on a backup server, the blast radius can reach beyond one machine. The backup environment can become a control point over recovery itself.

Four Veeam Backup & Replication vulnerabilities have been flagged by CISA in recent years as actively exploited in attacks, and BleepingComputer says all were abused by ransomware gangs. One example is CVE-2024-40711, a critical VBR RCE flaw that Sophos X-Ops reported in November 2024 had been weaponized by several ransomware operations, including Akira, Fog, and Frag.

Other groups have also been linked to attacks targeting VBR flaws. The source names FIN7, which often collaborated with Maze, Egregor, Conti, REvil, and BlackBasta, as well as the Cuba ransomware gang.

The scale raises the stakes. Veeam products are used by more than 550,000 customers worldwide, including 82% of Fortune 500 companies and 74% of Global 2,000 firms.

The practical question is not whether every exposed Veeam server will be attacked. It is whether defenders can patch faster than attackers can reverse-engineer the update and find reachable, domain-joined deployments.

Security teams should patch version 12 and challenge domain access

Administrators running affected Veeam Backup & Replication 12 builds should move to 12.3.2.4854 as a priority. Teams already on 13.x are outside the scope of this specific flaw, based on Veeam’s statement cited by BleepingComputer.

A useful first pass is narrow and fast:

  • Version check: Confirm whether any VBR server is running 12.3.2.4465 or an earlier version 12 build.
  • Domain status: Identify which backup servers are joined to a Windows domain.
  • Access review: Check which domain users and groups can authenticate to systems that host or manage backup infrastructure.
  • Patch coverage: Verify that all production and non-production VBR servers are updated, not just the primary system administrators remember first.

What should security teams review first after patching?

Start with the condition that makes this bug exploitable: authenticated domain access to a domain-joined backup server. XOOMAR analysis: because the flaw requires a domain user and affects domain-joined deployments, the most relevant immediate checks are authentication paths into backup servers, privileged access around VBR, and whether backup infrastructure is segmented from broader domain activity. The source does not report active exploitation, so defenders should avoid assuming compromise without evidence.

Veeam’s own warning is the near-term watch item. Patch releases can become exploit roadmaps for attackers hunting unpatched systems.

If public exploit code appears, or if ransomware crews begin using CVE-2026-44963 in intrusions, domain-joined VBR 12 servers that missed the update will move from “urgent patch” to “likely target.” For now, the cleanest move is simple: update Veeam, reduce domain exposure where possible, and treat backup servers as ransomware targets before attackers do.

Impact Analysis

  • Backup servers are high-value targets because they are critical to recovery during ransomware and breach response.
  • The flaw can be exploited by a low-privileged authenticated domain user, making it dangerous after initial network compromise.
  • Organizations running domain-joined Veeam 12.x servers should verify exposure and apply the fixed version quickly.

Veeam Backup & Replication Exposure by Version

Version/ConfigurationStatusRisk
Veeam Backup & Replication 12.3.2.4465 and earlier 12.x builds joined to a Windows domainAffectedAuthenticated low-privileged domain users may exploit RCE on the backup server
Veeam Backup & Replication 12.3.2.4854FixedPatch addresses CVE-2026-44963
Veeam Backup & Replication 13.xNot affectedArchitectural changes in version 13 prevent exposure
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Conceptual image showing the words 'Ethical Hacking' on a textured abstract background.Cybersecurity

Critical Gitea Bug Hijacks Systems for Crypto Mining

A critical Gitea vulnerability is under active attack, letting hackers hijack servers for cryptocurrency mining, confirmed by CISA's urgent patch order.

Aug 26, 20267 min
Close-up of a smartphone displaying a bank alert notification on a wooden table.Cybersecurity

Citrix Patch Fail Forces U.S. 72-Hour Crisis Ultimatum

A previously patched Citrix NetScaler flaw is being actively exploited, prompting a formal U.S. government emergency order giving all federal agencies just 72 h

Aug 27, 20268 min
Text 'Cyber Attack' on textured dark paper highlights digital security threat concept.Cybersecurity

Hackers Mass-Exploit Patched SharePoint Flaw After Public PoC

Attackers are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) using public proof-of-concept code, targeting organizations tha

Aug 13, 20265 min
A hacker in a black hoodie using a tablet displaying a skull, surrounded by chalk symbols and 'Hacker Attack' text.Cybersecurity

AI Wrote a Zoom Hack in Under 20 Prompts

Researchers weaponized a critical Zoom flaw using fewer than 20 AI prompts, collapsing the barrier to sophisticated cyberattacks and turning screen-sharing into

Aug 11, 20265 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Feds Set Deadline as Hackers Hit AI Tool, Web Server Code

The US government has issued a mandatory remediation deadline after confirming attackers are actively exploiting critical bugs in Langflow, Apache Tomcat, and N

Aug 6, 20265 min
Hurricane winds and torrential rain batter tropical coastline, illustrating infrastructure vulnerability during extreme weather events.Global Trends

Hurricane Lowell Cuts Power to 30,000 on Kauai

Hurricane Lowell's offshore winds knocked out power for 30,000 residents on Kauai, showcasing how vulnerable critical infrastructure is even without a direct la

Sep 9, 20268 min
Aerial view of hurricane aftermath on tropical island coastline with scattered debris and flooded infrastructure under dramatic skies.Global Trends

Kauai Left Powerless As Hurricane Lowell Skirts Islands

Hurricane Lowell passed west of Hawaii but crippled Kauai with near-total power loss and severe flooding, demonstrating the storm's wide, destructive reach.

Sep 9, 20264 min
A cinematic shot inside a high-tech financial data center, with abstract light visualizations representing volatile currency markets.Fintech

Poland's Final Inflation Bet Pays Off or Blows Up Soon

A massive bet on Polish rate hikes is clashing with central bank inaction, creating a volatile mispricing that could force a violent correction in the EUR/PLN p

Sep 9, 20267 min
Futuristic command center in Tokyo with holographic GDP charts, neural networks, and glowing circuits reflecting economic data innovation.Technology

Japan’s Final GDP Data Gives BOJ Green Light to Hike

Modest but surprising GDP growth data has removed the final obstacle for Japan's central bank to raise interest rates, shifting the market focus to what happens

Sep 9, 202610 min
Executive reviewing integrated ERP and accounts payable software interface on a tablet in a modern fintech office.Fintech

ERP Integration Defeats Price As Top AP Test

Most businesses now rank seamless software integration above price when buying accounts payable systems, a shift signaling that technical teams now hold decisiv

Sep 9, 20265 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.