← Back to list

CVE_2026_44963 Veeam RCE

CVE_2026_44963 Veeam Backup and Replication Authenticated RCE

suce · 2026-07-03 19:09 · 0 claps · 0.6 min read
#cve #rce #veeam #dotnet #deserialization
Open on Medium ↗

CVE_2026_44963 Veeam RCE

CVE_2026_44963 Veeam Backup and Replication Authenticated RCE

Introduction

Every sysadmin is familiar with Veeam’s enterprise backup solution, Veeam Backup & Replication. Unfortunately, so is attackers. Today, we’re going to look at the latest vulnerability — CVE-2026–44963. This vulnerability was reported by Sina Kheirkhah **@SinSinology of [WatchTowr](https://watchtowr.com/). Veeam advisory tells us that it affects version 12.3.2.4465 below and full patched at 12.3.2.4854. WatchTowr has already published 2 blog posts about previous RCEs, [CVE-2024–40711](https://labs.watchtowr.com/veeam-backup-response-rce-with-auth-but-mostly-without-auth-cve-2024-40711-2/) and [CVE-2025–23120](https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/)** which been a big help for understanding the .NET Remoting internals and .NET deserialization. Don’t forget to check them out.

Let’s start!

https://suce0155.github.io/posts/veeam_backup_rce/


메타데이터
post_id
2df483f88e8b
slug
cve-2026-44963-veeam-rce-2df483f88e8b
url
https://medium.com/@suce0155/cve-2026-44963-veeam-rce-2df483f88e8b
canonical_url
https://medium.com/@suce0155/cve-2026-44963-veeam-rce-2df483f88e8b
author_url
https://medium.com/@suce0155
status
ok
fetched_at
2026-07-09 03:40:04