INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Veeam Backup RCE Flaw Exploit Allows Remote Code Execution

| 2026-06-09 16:39 CRITICAL MEDIUM
Executive Summary AI-generated
The Veeam Backup & Replication RCE flaw, identified as CVE-2026-44963, has been exploited by bad actors including ransomware groups. This critical vulnerability allows remote code execution on the Backup Server, posing a significant threat to organizations with earlier versions of 12 builds and all previous versions of 12.x. The issue was addressed in Veeam Backup & Replication version 12.3.2.4854, but prior vulnerabilities have been exploited by malicious actors, including those involved in ransomware attacks. It is essential for users to update to the latest version for optimal protection against this threat.
Technical Mitigations AI-generated
• Update to the latest version of Veeam Backup & Replication. • Ensure that users are running a version prior to 12.3.2.4854, which is not affected by this vulnerability. Note: The text does not explicitly mention any specific technical mitigations beyond updating software versions or ensuring compatibility with earlier versions. However, the following general mitigation can be inferred: • Implement secure patching and update procedures for all systems and applications to ensure timely deployment of security patches. • Conduct regular system audits and monitoring to detect potential vulnerabilities before they are exploited. • Educate users on safe computing practices, such as avoiding suspicious links or attachments, and being cautious when interacting with unknown software.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
FIN7FIN7 ContiContiMazeMazeEgregorEgregorREvilREvil CVE-2024-40711CVE-2024-40711 CVE-2025-23121CVE-2025-23121 CVE-2026-44963CVE-2026-44963
Target & Sectors
Global Scope
Incident Timeline
‎November 2024
Threat actors exploited a previously unknown Remote Code Execution (RCE) flaw in Veeam Backup & Replication, allowing them to gain unauthorized access to vulnerable backup servers.
tactic Ransomware
organisation CVE-2024-40711
organisation VBR RCE
‎June 2025
Threat actors exploited a previously unknown vulnerability in Veeam's Backup & Replication solution to gain unauthorized access to backup servers.
organisation CVE-2025-23121
vulnerability CVSS score of 9.9
‎March 2026
Threat actors exploited a vulnerability in Veeam Backup & Replication software to gain remote access to affected backup servers.
tactic Remote Code Execution
‎Jun 09, 2026
Threat actors exploited a previously unknown Remote Code Execution (RCE) vulnerability in Veeam, allowing them to gain unauthorized access and potentially compromise backup servers.
‎2026/06/09
Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution.
threat_actor FIN7
organisation Ransomware
organisation BleepingComputer
organisation Vulnerability / Backup
organisation Backup & Replication
organisation the Backup
organisation CVE-2026-44963
infrastructure 9.4
organisation CVSS v4 Score
organisation CVSS
infrastructure 12.3.2
organisation Veeam Backup & Replication
organisation WatchTowr
organisation VBR
infrastructure Windows
organisation RCE
organisation EDR
victims 550,000 customers
organisation Active Directory
Tactical Metrics
Metrics
infrastructure
‎12.3.2
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
550,000
Customers
Metrics
infrastructure
‎9.4
Software Version
Intelligence Sources