Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
A serious vulnerability in Veeam's Backup & Replication software that might lead to remote code execution has been fixed with security patches.
The vulnerability, known as CVE-2026-44963, has a CVSS score of 9.4 out of a possible 10.0.
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user, Veeam said in a Tuesday advisory. Sina Kheirkhah, a watchTowr researcher, was credited with responsibly identifying and reporting the problem. Veeam Backup & Replication 12.3.2.4465 and all previous builds of 12 are affected.
Due to architectural modifications made in version 13, Veeam has observed that the vulnerability read more about Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
Get up to date on the&n...


