Critical Veeam Backup and Replication flaw on domain-joined servers

Veeam has issued a critical security advisory, documented in KB4869, covering CVE-2026-44963 in Backup & Replication. The vulnerability carries a CVSS score of 9.4 and allows an authenticated domain user to execute code remotely on the backup server. It specifically affects domain-joined backup servers running Veeam Backup & Replication version 12.3.2.4465 and all earlier version 12 builds.

What this means for your organisation

The backup server is the last thing you have left when something goes wrong, which is exactly why ransomware operators prioritise it. The bar here is low: an ordinary domain user suffices. If the backup server is joined to the same domain as everything else, a single compromised employee account reaches all the way to your recovery capability. Of everything in this round, this is the item with the greatest consequence if exploited.

Berigo recommends

  • Update Veeam Backup & Replication in line with KB4869 as fast as your change process allows.
  • Remove the backup server from the production domain, or move it to a separate administrative domain.
  • Ensure at least one copy of your backups is immutable and out of the domain's reach.
  • Test an actual restore from that copy, not merely that the jobs complete without errors.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch