CVE-2026-44963

Published Jun 9, 2026

Last updated 7 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-44963 is a remote code execution (RCE) vulnerability identified in Veeam Backup Server, specifically impacting Veeam Backup & Replication. This flaw, categorized as a deserialization of untrusted data (CWE-502), allows an authenticated domain user to execute arbitrary code on the affected backup server. The vulnerability requires low privileges, meaning an attacker only needs an authenticated domain account to exploit it. Successful exploitation can lead to the execution of arbitrary code under the privileges of the backup service, potentially affecting the confidentiality, integrity, and availability of the system and connected components. Veeam has released a security advisory and patches to address this issue.

Description
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
Source
support@hackerone.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

support@hackerone.com
CWE-502

Social media

Hype score
Not currently trending
  1. 企業のバックアップ基盤Veeamで、管理者権限を持たない一般のドメインユーザーからバックアップサーバー上のコード実行に至るCVE-2026-44963が修正されています。原因は、.NETの非推奨シリアライズ機構BinaryForma

    @MalwareBibleJP

    10 Jul 2026

    1924 Impressions

    2 Retweets

    13 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  2. #AppSec #Threat_Research 1⃣ Veeam Backup Authenticated RCE Explained https://t.co/KafXyR1QzA // CVE-2026-44963 2⃣ Multiple LPE Vulnerabilities in Little Orbit GFAC Driver (GFAC_Sys_x64.sys) https://t.co/cQUqtnYNNo 3⃣ Seven FatFs bugs, one very large blast radius

    @ksg93rd

    7 Jul 2026

    900 Impressions

    6 Retweets

    16 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2026-449: 🚨 A single domain user could run code on your Veeam Backup Server. Veeam has patched a critical RCE flaw (CVE-2026-44963, CVSS 9.4) in Backup & Replication. All v12 builds up to 12.3.2.4465 are affected. Fixed in 12.3.2.4854. v13.x is safe. Patch now:…

    @lyrie_ai

    6 Jul 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Most people will see the headline. The real signal is what Veeam CVE-2026-44963 puts domain… Veeam fixed CVE-2026-44963 in Backup & Replication 12.3.2.4854. 🔗 Details → https://t.co/eyv2BlX9LU

    @lucasverdan

    11 Jun 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Legacy exposure keeps paying off for attackers. Veeam CVE-2026-44963 puts domain-joined backup servers at… Veeam fixed CVE-2026-44963 in Backup & Replication 12.3.2.4854. Domain-joined backup server… 🔗 Read → https://t.co/ateGLTkHEH

    @fynn_JourX

    11 Jun 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🛑 Veeam CVE-2026-44963 puts domain-joined backup servers at RCE risk Veeam fixed CVE-2026-44963 in Backup & Replication 12.3.2.4854. Domain-joined backup server… 🔗 Details → https://t.co/eyv2BlX9LU

    @lucasverdan

    11 Jun 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. For defenders, veeam cve-2026-44963 puts domain-joined backup servers at rce r… should move fast. Veeam fixed CVE-2026-44963 in Backup & Replication 12.3.2.4854. Domain-joined backup server… 🔗 Details → https://t.co/HwuNMSKfHk

    @SocXAInvaders

    11 Jun 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Three critical RCEs worth dropping everything for this week: Ivanti Sentry, CVE-2026-10520 (CVSS 10): unauthenticated, root-level command injection. Public PoC is already out. Patch 10.5.2 / 10.6.2 / 10.7.1. Veeam Backup & Replication, CVE-2026-44963 (CVSS 9.4): any https:/

    @PurpleOps_io

    10 Jun 2026

    139 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. 🔒 #CyberSecurity CVE-2026-44963: Veeam Backup & Replication Critical RCE — Detection and Hardeni… "Critical Veeam flaw CVE-2026-44963 (CVSS 9.4) allows authenticated domain…" 🔗 https://t.co/29ddtjejkd #CyberSecurity #ThreatIntel #sigmarule #kqldetection #threa

    @SecurityAr58409

    10 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. The floor opens up under Veeam — again. CVE-2026-44963, remote code execution on Backup & Replication, disclosed today by Sina Kheirkhah at WatchTowr. Any authenticated domain user. Any low-privilege account. Line-of-sight to the VBR server and you have RCE. Affects all v12

    @GoCocoaAI

    9 Jun 2026

    144 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

References

Sources include official advisories and independent security research.