EXECUTIVE SUMMARY
A critical security vulnerability has been identified in Veeam Backup & Replication that could allow attackers to achieve remote code execution (RCE) on vulnerable backup servers. The flaw affects domain-joined Veeam Backup & Replication installations and can be exploited by an authenticated domain user to execute arbitrary code with elevated privileges on the backup infrastructure.
- CVE: CVE-2026-44963
- CVSS Score: 9.4
- Affected Region: Global
- Affected Sector: All industries utilizing Veeam Backup & Replication.
- Affected Product: Veeam Backup & Replication
- Impact: Remote Code Execution (RCE)
- Severity: Critical
- Published Date: June 10, 2026
TECHNICAL DETAILS
The flaw affects domain-joined backup servers running vulnerable 12.x versions of the software and allows an authenticated domain user to perform remote code execution (RCE) on the backup server.
- Root Cause: The vulnerability exists within Veeam Backup & Replication and can be exploited by an authenticated domain user to execute arbitrary code on a domain-joined backup server. Veeam has not publicly disclosed detailed technical information regarding the underlying flaw; however, successful exploitation may result in remote code execution on the affected system.
- Target: The primary targets are Veeam Backup & Replication servers, particularly domain-joined backup servers running vulnerable 12.x versions. Attackers target these systems because they contain backup data, privileged credentials, configuration information, and recovery assets that are critical to business operations and disaster recovery processes..
- Prerequisites for Exploitation: To successfully exploit this vulnerability, the target must be running a vulnerable version of Veeam Backup & Replication on a server joined……



