SOC status: Operational/Continuous monitoring active

Acronis MDR / XDR available +230 5254 7558

HighAdvisoryTLP: CLEARCBN-2026-026 · 10 Jun 2026

Two rounds of critical Veeam flaws, all exploitable by any ordinary domain user

Veeam Backup & Replication took seven critical vulnerabilities in March and another remote code execution flaw in June. Every one of them needs only a low-privilege authenticated domain account — which means one phished user reaches your backup server.

At a glance

Affected

Veeam Backup & Replication 12.3.2.4465 and earlier v12 builds for the June flaw; 12.3.2.4165 and earlier for the March round. Only domain-joined backup servers are exposed.

Impact

Code execution on the platform that holds your last line of recovery, plus repository file manipulation and local privilege escalation on Windows.

Action

Update to 12.3.2.4854 or 13.0.1.2067. Then do the thing that actually removes the class: take the backup server off the Windows domain.

Client status

Acronis-protected estates are unaffected — different platform. Clients running Veeam alongside should confirm both the build and whether the backup server is domain-joined.

Detail

Read the affected-configuration line on any of these advisories and the same phrase appears: an authenticated domain user, on a domain-joined backup server. Not an administrator. Not someone with backup permissions. Any account in the directory.

That is the whole story. In a domain-joined design, the blast radius of a single phished standard user includes code execution on the system holding every restore point you own. Four of the March vulnerabilities scored 9.9 for exactly this reason: the attack complexity is low and the privilege requirement is nearly nothing.

The design decision matters more than the patch

Patch to 12.3.2.4854 or 13.0.1.2067 — obviously, and quickly, because Veeam itself warns that attackers reverse-engineer these fixes fast. But patching addresses these eight CVEs. Removing the backup server from the Windows domain addresses the category, including the ones not yet disclosed.

A workgroup or separately-domained backup server, on an isolated management VLAN reachable only through a hardened jump host, with its own non-reused credentials behind phishing-resistant MFA, is not exposed to "authenticated domain user" at all. It is more work to run. It is also the difference between an incident and a disaster.

The historical record is not encouraging

None of the 2026 flaws were confirmed as exploited in the wild at disclosure. That is worth stating plainly, and it is also worth remembering what happened with CVE-2024-40711: Akira, Fog and Frag all exploited it to reach backup servers ahead of encryption, and earlier Veeam bugs drew FIN7, Maze, Egregor, Conti, REvil, Black Basta and Cuba. Ransomware crews target backup platforms because destroying recovery is what converts an outage into a payment. Veeam reports over 550,000 customers, including 82% of the Fortune 500 — the incentive to weaponise these is substantial.

NHS England issued its own cyber alert to the UK health sector over the critical Backup & Replication flaw, which gives a sense of how sector regulators are reading the risk.

If you find evidence of this activity, do not begin remediation before preserving evidence — console and appliance audit logs are frequently short-retention and will roll off. Acronis MDR provides around-the-clock detection and response for covered estates; otherwise reach us through the contact page and we will advise on preservation before containment.

Sources

Cybernalyst's analysis and recommendations are our own. The underlying research is credited below — please read the original reporting.

  1. Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code ExecutionRavie Lakshmanan·The Hacker News·13 March 2026
  2. New Veeam vulnerability exposes backup servers to RCE attacksSergiu Gatlan·BleepingComputer·9 June 2026
  3. Veeam Releases Security Advisory for Critical Vulnerability in Backup & Replication (CC-4794)NHS England Digital·2026