VDB
CVE-2026-44963
CVE-2026-44963
PUBLISHED
CVSS 9.399999618530273 CRITICAL
CVE-2026-44963 is a Critical (CVSS:4.0 9.4) deserialization vulnerability that allows an authenticated domain user to achieve remote code execution on the Backup Server over the network, with no elevated privileges required beyond standard domain credentials. Version 13.x is not impacted by this vulnerability due to architectural changes introduced in that release.
Risk Scores
CVSS 4.0
9.399999618530273
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Veeam | Veeam Backup & Replication versions 12, 12.1, 12.2, 12.3, 12.3.1, 12.3.2 |
Timeline
- Jun 9, 2026 CVE Published
- Jun 10, 2026 Coalition ESS Score
- Jun 10, 2026 CVE Updated
- Jun 12, 2026 Security Advisory
References
- https://ccb.belgium.be/advisories/warning-critical-remote-code-execution-veeam-backup-replication-patch-immediately advisory
- https://www.veeam.com/kb4869 vendor
- https://bp.veeam.com/security/Design-and-implementation/Hardening/Workgroup_or_Domain.html#best-practice technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-44963 technical