Veeam has patched a critical RCE vulnerability (CVE-2026-44963) in Backup & Replication versions up to 12.3.2.4465. Any authenticated domain user with low privileges can exploit the flaw on domain-joined VBR servers. The fix is available in version 12.3.2.4854, and version 13.x is unaffected due to architectural changes. No active exploitation has been reported yet, but Veeam warns attackers typically reverse-engineer patches quickly. Veeam backup servers are a high-value ransomware target — CISA has flagged four prior VBR flaws as actively exploited, with groups like Akira, Fog, Frag, FIN7, and Cuba ransomware previously weaponizing similar vulnerabilities.
296 Impressions