Veeam Backup and Replication CVE-2026-44963: CVSS 9.4 RCE Flaw Affects Every GCC Enterprise Running Veeam

Veeam has patched CVE-2026-44963, a critical CVSS 9.4 RCE vulnerability in Backup and Replication allowing authenticated domain users to execute arbitrary code. With Veeam protecting 82% of the Fortune 500, GCC enterprises must update to version 12.3.2.4466 or above immediately.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
GCC enterprise IT administrator reviewing Veeam backup management alerts following disclosure of critical remote code execution vulnerability CVE-2026-44963 with CVSS score 9.4 in June 2026

GCC enterprise IT administrator reviewing Veeam backup management alerts following disclosure of critical remote code execution vulnerability CVE-2026-44963 with CVSS score 9.4 in June 2026

Veeam has released an emergency patch for CVE-2026-44963, a critical remote code execution vulnerability in its Backup and Replication software carrying a CVSS score of 9.4 out of 10. The flaw allows any authenticated domain user to execute arbitrary code on the backup server, meaning a single compromised employee account anywhere in a connected domain is sufficient to gain full control of an organisation's backup infrastructure.

Veeam credited watchTowr researcher Sina Kheirkhah for discovering and responsibly disclosing the vulnerability. The company confirmed the flaw affects all Veeam Backup and Replication versions up to and including 12.3.2.4465 on version 12 builds. Version 13 builds are not affected due to architectural changes introduced in that release.

The patch is contained in version 12.3.2.4466, released on 10 June 2026.

Why This Is a Priority Patch for GCC Enterprises

Veeam Backup and Replication is the dominant backup and recovery platform across Gulf enterprise environments. Veeam's own figures place it as the global market leader in data resilience, protecting over 450,000 customers worldwide including 82% of the Fortune 500 and 72% of the Global 2000. In the GCC, Veeam is the standard backup solution across financial services, government, healthcare, energy, and retail sectors.

The specific nature of CVE-2026-44963 makes it particularly dangerous in the context of ransomware operations. Ransomware actors systematically target backup infrastructure before deploying their encryption payloads. The ability to execute arbitrary code on the backup server as part of the attack chain means that an organisation's ransomware recovery capability can be destroyed before the primary attack is even visible to defenders.

The Gulf ransomware context is directly relevant here. UAE organisations pay 92% of ransom demands, above the global average of 85%, according to Sophos data. The single most cited reason enterprises pay ransoms rather than recovering is that backup systems either failed or were themselves compromised. CVE-2026-44963 provides exactly the mechanism through which a threat actor inside a domain can ensure that recovery is not an option.

This is not a theoretical risk. Backup and recovery infrastructure has been targeted in GCC ransomware campaigns documented by Help AG's 2026 State of the Market Report, which confirmed that several major compromises in the region reached full operational impact, including backup system destruction, in under 40 hours from initial access. As the UAE Cyber Security Council has confirmed, the country is absorbing between 600,000 and 800,000 breach attempts every single day, a volume that underscores why hardening recovery infrastructure is as critical as securing the perimeter. For broader context on how backup targeting fits into the regional threat landscape, the MENA Cyber Wire analysis of the UAE Government Cybersecurity Summit 2026 covers the shifting composition of attacks against Dubai and Abu Dhabi infrastructure in detail.

What to Do Now

Apply the patch immediately. Update all Veeam Backup and Replication deployments running version 12 builds to version 12.3.2.4466. The patch is available through Veeam's standard update mechanism and the Veeam support portal.

Organisations that cannot apply the patch immediately should restrict access to the backup server to named backup administrator accounts only, and review Active Directory for any domain accounts with unnecessary access to backup infrastructure. The attack path requires an authenticated domain user, so reducing the set of accounts that can reach the backup server is the most effective interim control.

Check Point CVE-2026-50751, disclosed this week, followed a similar pattern of attackers targeting network infrastructure before moving to high-value enterprise systems. As documented in the Trellix source code breach investigation, GCC enterprises using widely deployed security and infrastructure vendors must treat any unpatched vulnerability in a privileged platform as an active threat. Backup servers represent the same category of high-value target and deserve the same urgency of response.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

GCC Threat IntelligenceRansomware in the GulfEnterprise Patch ManagementCyber Resilience Middle EastMENA Enterprise Security