Veeam Patches 9.4-Severity RCE in Backup & Replication; Domain Auth Required

CVE-2026-44963 lets any authenticated domain user run code on the backup server. Veeam shipped fixes Tuesday.

ThreatVectr Newsdesk· 2 min read
Veeam Patches 9.4-Severity RCE in Backup & Replication; Domain Auth Required
Share

Veeam has patched a critical remote code execution flaw in Backup & Replication that any authenticated domain user can exploit against the backup server itself.

The bug is tracked as CVE-2026-44963 and carries a CVSS score of 9.4.

Veeam disclosed the issue in a Tuesday advisory, describing it as "a vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user." The vendor's own write-up is published on the Veeam Knowledge Base.

That authentication requirement is thinner than it sounds. In most enterprise deployments, the Veeam backup server is domain-joined. Any user with a valid domain account — interns, contractors, service accounts whose credentials are sitting in a script somewhere — meets the bar. Lateral movement scenarios get ugly fast.

Why this one matters

Backup infrastructure is the prize target in modern intrusions. Ransomware crews from Akira to Black Basta to the remnants of LockBit routinely hunt Veeam servers before detonating payloads, because killing or encrypting backups is what forces the ransom payment. A pre-encryption RCE on the backup controller is exactly the primitive affiliates pay initial access brokers for.

Prior Veeam bugs have a track record of being weaponised quickly. CVE-2023-27532 was folded into FIN7 tooling within months of disclosure. CVE-2024-40711 showed up in Akira and Fog ransomware intrusions almost immediately after a public proof-of-concept dropped. There is no reason to assume CVE-2026-44963 will sit idle.

What to do

Veeam is directing customers to the fixed builds listed in its advisory. Administrators should:

  • Patch Backup & Replication to the latest build immediately.
  • Audit which domain accounts can authenticate to the backup server, and remove any that don't need to.
  • Consider moving the backup server off the production domain entirely. Veeam has recommended a workgroup or dedicated management domain in its hardening guidance for years. Many shops still ignore it.

No in-the-wild exploitation has been confirmed at time of writing. The vendor has not credited an external researcher in the public advisory, which suggests the flaw was found internally or reported privately without attribution.

Veeam claims more than 550,000 customers globally, including a majority of the Fortune 500. The install base is the story. So is the speed at which ransomware affiliates reverse-engineer these patches.

Expect a working exploit within weeks.

© 2026 Threat Vectr