---
schema: 1
kind: vulnerability
title: "CVE-2026-44963 — Veeam Backup & Replication: authenticated domain-user deserialization RCE on the backup server (CVSS 9.4)"
headline: "CVE-2026-44963 — Veeam Backup & Replication: authenticated domain-user deserialization RCE on the backup server (CVSS 9.4)"
summary: "Veeam patched CVE-2026-44963 (CVSS v4 9.4, CWE-502) on 9 June: any authenticated domain user — no elevated Veeam privilege required — can execute code on the Backup Server when it is domain-joined; workgroup servers are unaffected (Veeam, 2026-06-09)."
discovered_at: "2026-06-10T05:00:08Z"
event_date: 2026-06-09
run_id: 2026-06-10-c84347b2
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - ransomware
regions:
  - global
sectors:
  - public-sector
entities:
  - "actor:akira"
cves:
  - id: CVE-2026-44963
    cvss: "9.4"
    epss: null
    type: rce
    vector: local
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://www.veeam.com/kb4869"
    publisher: "Veeam, 2026-06-09"
    role: primary
  - url: "https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html"
    publisher: "The Hacker News, 2026-06-09"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-10.md
---

Veeam patched CVE-2026-44963 (CVSS v4 9.4, CWE-502) on 9 June: any authenticated domain user — no elevated Veeam privilege required — can execute code on the Backup Server when it is domain-joined; workgroup servers are unaffected ([Veeam, 2026-06-09](https://www.veeam.com/kb4869)). It affects all v12 builds up to 12.3.2.4465 (fixed in 12.3.2.4854); v13.x is not affected. Reported by watchTowr's Sina Kheirkhah ([The Hacker News, 2026-06-09](https://thehackernews.com/2026/06/veeam-backup-replication-rce-flaw-lets.html)). No ITW exploitation is confirmed, but backup infrastructure is a perennial pre-encryption ransomware target (Akira, Black Basta, LockBit have historically gone after Veeam first), so treat as urgent (T1210, T1486). Upgrade to 12.3.2.4854; where patching is blocked, Veeam's hardening guidance includes removing the backup server from the domain.
