[CIVN-2026-0315] Remote Code Execution Vulnerability in Veeam Backup & Replication

By Published On: June 16, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Remote Code Execution Vulnerability in Veeam Backup & Replication


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Veeam Backup & Replication 12.3.2.4465 and all earlier Version 12 builds.

Overview


A vulnerability has been reported in Veeam Backup & Replication which could be exploited by an authenticated domain user to execute arbitrary code on the targeted system.


Target Audience:

Enterprises and large Organizations, cloud service providers (CSPs), and backup administrators utilizing domain-joined Veeam Backup & Replication systems.


Risk Assessment:

Critical risk of remote code execution (RCE) resulting in potential compromise of backup infrastructure.


Impact Assessment:

Unauthorized code execution, backup data deletion or modification, and potential domain lateral movement.


Description


Veeam Backup & Replication is a data protection solution that provides backup, recovery, and replication capabilities.


This vulnerability exists in Veeam Backup & Replication and can be exploited by an authenticated domain user to achieve Remote Code Execution (RCE) on the targeted backup server.


Successful exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary code on the targeted system.


Solution


Apply appropriate software updates as mentioned:

https://www.veeam.com/kb4869



Vendor Information


Veeam

https://www.veeam.com/kb4869


References


 

https://www.veeam.com/kb4869


CVE Name

CVE-2026-44963




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoxaBcACgkQ3jCgcSdc

ys//Iw/+NOhMUoiWOFtr4eLDgAOI51yz9XLKNAYfeXlWUwderoG8nU0CGayu9C5L

wM73iROpnxvf9gWuw5n1vxOwZAM/VO0giZ8eDAf38rkU4e3yYoh2m8Wu9ZqrZ7Sa

2UvJm/qGGMtKUteCkr/2MG5eppFTEoVvlwihh1yMeMhjPpu/vVyCUTfXr5Y3Zc0t

AXepv+RMHnRNJcTItvvgaQ7IjLe2WHaigVgPs5InfKmupaEPmL6M63ZxcZDaM0w9

Vv0Fg5LXy33x/HbZnflcVpSUPZ3xIMlDLq4jF5S0dIVLwaC2BsuYG+q5+z5sBvO7

XgJcSXN2bbWIgmbi0KtN77M4sUJktviMaOnJDEpoNxwCvprThxEWrYHV0H7Q0ECs

z9kVMyv6euwrHcP7B9YlFw3pBjB3Ae4QT7bcnP93DEC1si1tNHrKnzS6YyoCxuKa

uWkbS6ygyJxgoUhN1M/+FRGYR18mGkDG5JwOKPp9iZYtBpGOU8FvGOVqsP1zwuAK

SADnEqRYisWPXRoS6kX0jSoXSyuTdZGOt0NLx19zcXk/Hv69ZyzdzoJLvmErNk0Y

HR1cBY0Zhhc7zVYt5MHWjGiDpT3D0SnoMUlb6i4uMrd+J2AQVS+zsRua12pXgAmK

YQs3ULMmEB5A8r1wlwJRsdcOsuX3etXAxBp04fIJjpGVt1zqzVQ=

=OhN7

—–END PGP SIGNATURE—–

Share this article