ZeroHour
Security Affairspublished ()ingested @securityaffairs

Critical Veeam RCE flaw Lets Low

criticalVulnerability exploited in the wildimportance 60CVE-2026-44963CVE-2025-23121

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-23121
Authenticated Domain-User RCE in Veeam Backup & Replication

CVE-2025-23121 is a code-injection vulnerability (CWE-94) in Veeam Backup & Replication that allows an authenticated domain user to execute arbitrary code on the Backup Server over the network. An attacker triggers it by sending a crafted request to the backup server's network-facing components using valid, low-privileged domain credentials, with no user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity and availability of the backup server (CVSS 3.1: 8.8 per the vector provided, though some coverage lists a 9.9 score). Any organization running Veeam Backup & Replication is affected, particularly environments where many or low-privilege domain accounts can reach the backup server. As of this writing it is not in CISA KEV and no public PoC is known, but the EPSS of 22.2% (98th percentile) indicates an elevated probability of exploitation within the next 30 days, and Veeam has shipped a fix.

Do: Upgrade Veeam Backup & Replication to the latest patched release per Veeam's security advisory for CVE-2025-23121. In the meantime, restrict which domain accounts can authenticate to the Backup Server, ensure the server is not exposed to the public internet, and audit for unusual process execution or network connections from backup infrastructure. Given the high EPSS score, prioritize patching and monitor Veeam/Kev feeds for signs of in-the-wild exploitation.

8.822%
  • Veeam Backup & Replication (Backup Server component)
mass≈ hundreds of thousands of backup-server deployments (order of 10^5–10^6 installations)
CVE-2026-44963
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

NVD description · AI analysis pending
9.42%
Full article362 words · extracted from securityaffairs.com · click to collapse

Veeam addressed a critical RCE vulnerability flaw in Backup & Replication that lets low-privileged domain users take control of backup servers.

Veeam has patched a critical remote code execution vulnerability, tracked as CVE-2026-44963 (CVSS v4 Score of 9.4), affecting Backup & Replication version 12.x. The flaw could allow a low-privileged domain user to execute code on backup servers connected to an Active Directory domain, potentially leading to full system compromise.

The issue was fixed in version 12.3.2.4854 and does not affect Veeam Backup & Replication 13.x, which uses a different architecture.

WatchTowr researcher Sina Kheirkhah [@SinSinology] reported the issue.

“A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.” reads the advisory.

At this time, the vendor is not aware of any in-the-wild attacks exploiting this vulnerability. However, it warns that threat actors may begin exploiting it as soon as patches are released.

“It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software.” continues the advisory. “This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.”

Ransomware and extortion groups often target Veeam Backup & Replication because backup systems are a critical part of an organization’s recovery process. If attackers compromise them, they can delete or encrypt backups, steal sensitive data stored in backup archives, and extract credentials that help them move deeper into the network. This makes recovery much harder and increases pressure on victims to pay. Veeam servers are especially attractive because they usually have high privileges and broad access to virtual machines and storage systems. As a result, attackers prioritize backup infrastructure early in their attack chain to weaken defenses before deploying ransomware.

In June 2025, Veeam rolled out security patches to address another critical security vulnerability, tracked CVE-2025-23121 (CVSS score of 9.9) in its Backup & Replication solution that can allow remote attackers to execute arbitrary code under certain conditions.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/193385/security/critical-veeam-rce-flaw-lets-low-privilege-users-take-over-backup-servers.html