Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities NCSC Netherlands

NCSC-2026-0188 [1.00] [M/H] Kwetsbaarheid verholpen in Veeam Backup & Replication

A critical deserialization vulnerability (CVE-2026-44963, CVSS v4 9.4) in Veeam Backup & Replication allows authenticated domain users to achieve remote code execution on the Backup Server, potentially compromising backup integrity and availability. The article references a vendor patch but does not specify the affected or fixed version ranges. Administrators should immediately consult Veeam knowledge base article KB4869 for remediation details.
Read Full Article →

Security Advisories Download Security Advisory; NCSC-2026-0188 [1.0.0] Security Advisory NCSC-2026-0188 [1.0.0] Publicatie 10-06-2026 14:02 (Europe/Amsterdam) Prioriteit Normaal Betreft Kwetsbaarheid verholpen in Veeam Backup & Replication Kenmerken Deserialization of Untrusted Data Omschrijving Veeam heeft een kwetsbaarheid verholpen in Backup & Replication De kwetsbaarheid maakt het mogelijk voor een geauthenticeerde domeingebruiker om remote code uit te voeren op de Backup Server. Hierdoor kan een aanvaller met domeinreferenties de kwetsbaarheid benutten om controle te krijgen over backup-operaties. Dit betreft een kwetsbaarheid in de backup server software die invloed heeft op de integriteit en beschikbaarheid van backupdata. Oplossingen De leverancier heeft updates uitgebracht om de kwetsbaarheid te verhelpen. Zie bijgevoegde referenties voor meer informatie. Referenties https://www.veeam.com/kb4869 CVE's CVE-2026-44963 - CVSS (v4) 9.4 Producten Veeam Backup & Replication Disclaimer The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions: NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein. NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory. This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.

Share this article