Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Veeam releases security update for critical backup server vulnerability

A critical vulnerability in Veeam Backup & Replication (CVE-2026-44963) allows authenticated domain users to achieve remote code execution on domain-joined backup servers. The flaw affects VBR versions 12.3.2.4465 and earlier, with the fix available in version 12.3.2.4854. Veeam advises patching immediately, as ransomware groups historically target such flaws to delete backups and move laterally.
Read Full Article →

Vulnerability Management Veeam releases security update for critical backup server vulnerability June 9, 2026 Share By SC Staff (Adobe Stock) Coverage from Bleeping Computer indicates that Veeam has released security updates to address a critical vulnerability in its Backup & Replication software. This flaw, if exploited, could allow an authenticated domain user to achieve remote code execution on domain-joined backup servers. The vulnerability, tracked as CVE-2026-44963, affects Veeam Backup & Replication (VBR) versions 12.3.2.4465 and earlier, with the fix available in version 12.3.2.4854. While Veeam's best practice is to avoid joining backup servers to a Windows domain, many organizations have done so. This makes them susceptible to exploitation by low-privilege domain users. Although there are no current reports of active exploitation, Veeam warns that attackers often develop exploits once patches are disclosed. Ransomware gangs frequently target Veeam backup servers to steal data, move laterally within networks, and delete backups to hinder recovery. The Cybersecurity and Infrastructure Security Agency (CISA) has previously flagged four VBR flaws as actively exploited, often by ransomware groups such as Akira, Fog, and Frag. The FIN7 threat group and the Cuba ransomware gang have also been linked to attacks exploiting VBR vulnerabilities. Veeam's software is widely used, with over 550,000 customers globally, including a significant percentage of Fortune 500 and Global 2,000 companies. Source: Bleeping Computer SC Staff Related Patch/Configuration Management Windows 10 KB5094127 update fixes vulnerabilities, enhances Secure Boot monitoring SC Staff June 9, 2026 The KB5094127 update primarily focuses on security enhancements and bug fixes, as Microsoft is no longer introducing new features to Windows 10. Vulnerability Management CISA adds Check Point VPN bug to list of exploited vulnerabilities Steve Zurier June 9, 2026 CISA warns of an exploited Check Point VPN flaw that lets attackers bypass authentication. Vulnerability Management Google releases emergency update for fifth Chrome zero-day exploited in the wild this year SC Staff June 9, 2026 The vulnerability, identified as CVE-2026-11645, is a high-severity out-of-bounds read and write weakness within Chrome's V8 JavaScript engine. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article