VYPR
Critical severityNVD Advisory· Published Jun 9, 2026· Updated Jun 10, 2026

CVE-2026-44963

CVE-2026-44963

Description

Critical RCE vulnerability in Veeam Backup & Replication 12.x allows authenticated domain users to compromise the backup server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Critical RCE vulnerability in Veeam Backup & Replication 12.x allows authenticated domain users to compromise the backup server.

Vulnerability

A critical vulnerability exists in Veeam Backup & Replication versions 12.3.2.4465 and all earlier version 12 builds, allowing for remote code execution on the Backup Server. This vulnerability does not affect version 13.x due to architectural changes. Unsupported product versions are also likely affected [1].

Exploitation

An attacker with authenticated domain user privileges can exploit this vulnerability remotely. The specific steps required for exploitation are not detailed in the available references, but the CVSS vector indicates a low attack complexity and no user interaction is needed [1].

Impact

Successful exploitation of this vulnerability grants an attacker the ability to execute remote code on the Backup Server. This can lead to a high impact on confidentiality, integrity, and availability, potentially resulting in a full compromise of the backup server and its data [1].

Mitigation

Veeam Backup & Replication 12.3.2.4854 resolves this vulnerability. Version 13.x is not affected. Customers are urged to update to the latest version to safeguard their systems. No workarounds are mentioned, and unsupported versions should be considered vulnerable [1].

AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

3