CVE-2023-27532Disclosure(veeam / veeam_backup_\&_replication)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch veeam veeam_backup_\&_replication systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-09-12. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • veeam_backup_\&_replication

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 8 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 1 mentions (2026-02-25); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Vendors
Products
veeam_backup_\&_replication

2 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-02-25: 1Mentions · 2026-05-20: 1Mentions · 2026-06-09: 1Mentions · 2026-07-13: 1Mentions · 2026-08-20: 1Mentions · 2026-08-23: 1Mentions · 2026-09-09: 1Mentions · 2026-10-01: 1PoC Mentioned / Linked · 2026-09-09: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-05-20: 1Technical Details · 2026-07-13: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-23: 102-2505-2006-0907-1308-2008-2309-0910-01
Signal classification6 categories
Disclosure
228.6%
Patch
114.3%
General
114.3%
Disclousure
114.3%
Active Exploitation
114.3%
PoC
114.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-05-201
Disclosure1
2026-06-091
General1
2026-07-131
Disclousure1
2026-08-201
Active Exploitation1
2026-08-231
Disclosure1
2026-09-091
PoC1
Full discourse8 posts
  • mRr3b00t@UK_Daniel_Card
    PoC

    The non AI toolkit: Mimikatz SharpHound Certipy BloodHound Legacy Rubeus Impacket NetExec SpoolSample Certipy (source) BloodHound CE Mimikatz (source) BloodHound (py) Seatbelt Certify SharpSploit Empire VeeamDumper SharpVeeamDecryptor CVE-2023-27532 (PoC 1) Veeam Backup and Replication CVE-2023-27532 (PoC 2) Veeam Backup and Replication pyVmomi govmomi EDR2trash Disable-TamperProtection AMSI Bypass PowerShell please note these parts are all standard pentest/hacking tools! (not AI)

    Post summary

    The post lists numerous pentest tools and notes that two proofs‑of‑concept exist for CVE‑2023‑27532 in Veeam Backup & Replication.

    10052470
    126.0K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclousure

    A critical Veeam Backup vulnerability (CVE-2026-44963) allows remote code execution. Patch immediately to avoid ransomware targeting CVE-2023-27532. #Veeam #CVE202644963 #CyberSecurity #RCE #Vulnerability http://securityonline.info/cve-2026-44963-veeam-rce/

    Post summary

    The tweet announces a critical Veeam Backup RCE vulnerability (CVE‑2026‑44963) and urges users to patch immediately, but it does not provide a PoC, exploit code, or evidence of active exploitation.

    01011654
    12.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-44963, a CVSS 9.4 deserialization RCE in Veeam Backup & Replication 12.x, is actively referenced by Lynx Ransomware in negotiations, with unverified claims of a patch-bypass variant circulating on criminal forums. - CVE-2026-44963 abuses unsafe deserialization via BinaryFormatter/.NET Remoting (CWE-502). Any low-privilege domain user can achieve SYSTEM-level RCE on domain-joined Veeam servers running 12.x up to build 12.3.2.4465. Fixed in 12.3.2.4854 (June 2026). Version 13.x is not affected. Workgroup deployments are not vulnerable to this specific flaw. - Lynx Ransomware operators described exploiting Veeam to RCE, creating a local admin account, then dumping backup and domain admin credentials for full network compromise. They claimed a private unauthenticated variant that bypasses the patch. Unverified as of mid-August 2026, but a September 2025 underground sale matching the same privilege level and impact suggests CVE-2026-44963 was privately traded before official disclosure. - Credential harvesting from Veeam.Backup.Service.exe via CVE-2023-27532 remains the most common Veeam attack vector across ransomware groups, used in over 70% of observed cases. Backup servers are prioritized because attackers gain hypervisor credentials, can delete repositories, and destroy recovery options before deploying ransomware. Patch to 12.3.2.4854 immediately. #DFIR_Radar

    Post summary

    CVE‑2026‑44963 is a high‑severity deserialization RCE in Veeam Backup 12.x, actively exploited by Lynx ransomware operators, with a known patch available to mitigate the vulnerability.

    11000222
    1.9K followersView on X
  • elhackeretico_oficial@elhackeretico
    Disclosure

    La escalada final se consigue abusando de una versión vulnerable de Veeam Backup & Replication. Mediante CVE-2023-27532, se logra ejecución de comandos bajo el contexto de NT AUTHORITY\SYSTEM.

    Post summary

    El mensaje describe cómo el CVE-2023-27532 de Veeam Backup & Replication permite ejecutar comandos con privilegios SYSTEM, evidenciando una vulnerabilidad de escalada de privilegios.

    10000120
    4.8K followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2023-27532 Product: Veeam / Backup & Replication Summary: VulnCheck reports real-world exploitation activity affecting Veeam / Backup & Replication. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 26 Apr 2023 Source: https://vulncheck.com/xdb/70b9158e5d47 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Veeam #BackupReplication #CVE_2023_27532 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000041
    226 followersView on X
  • RST Cloud@rst_cloud
    Disclosure

    #threatreport #HighCompleteness VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | 20-08-2026 Source: https://theravenfile.com/2026/08/20/veeam-under-fire-understanding-cve-2026-44963-ransomware-group-exploit-claims/ Key details below ↓ 🧑‍💻Actors/Campaigns: Lynx_ransomware Carbanak Dragonforce Vice_society Lazarus Bluenoroff Warlock Hunters_international Teampcp 💀Threats: Lynx, Akira_ransomware, Fog_ransomware, Credential_harvesting_technique, Credential_dumping_technique, Qilin_ransomware, Rclone_tool, Conti, Blackbasta, Kerberoasting_technique, Bitsadmin_tool, Pdq_deploy_tool, Cuba_ransomware, Cobalt_strike_tool, Bughatch, Burntcigar, Metasploit_tool, Defendercontrol_tool, Veeamhax, Anydesk_tool, Simplehelp_tool, Medusa_ransomware, Clop, Lemurloot, Rhysida, Secretsdump_tool, Putty_tool, Nltest_tool, Ransomhub, Lockbit, Dcsync_technique, Gentlekiller, Av-killer, Hexkiller, Throttleblood, Havockiller, Oxideharvest, Impacket_tool, Wmiexec_tool, Netexec_tool, Inc_ransomware, Anubis, Dire_wolf, Wevtutil_tool, Shadow_copies_delete_technique, Vssadmin_tool, Everest_ransomware, Supply_chain_technique, 🎯Victims: Data backup and recovery sector 🏭Industry: Critical_infrastructure 🌐Geo: Dprk, Latin american 🔓CVEs: CVE-2023-3519 \[[Vulners](https://vulners.com/cve/CVE-2023-3519)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - citrix netscaler_application_delivery_controller (<12.1-55.297, <13.0-91.13, <13.1-37.159, <13.1-49.13) - citrix netscaler_gateway (<13.0-91.13, <13.1-49.13) CVE-2026-44963 \[[Vulners](https://vulners.com/cve/CVE-2026-44963)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True CVE-2026-12569 \[[Vulners](https://vulners.com/cve/CVE-2026-12569)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ptc flexplm (le11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0) CVE-2023-34362 \[[Vulners](https://vulners.com/cve/CVE-2023-34362)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - progress moveit_cloud (<14.0.5.45, <14.1.6.97, <15.0.2.39) - progress moveit_transfer (<2021.0.7, <2021.1.5, <2022.0.5, <2022.1.6, <2023.0.2) CVE-2023-27532 \[[Vulners](https://vulners.com/cve/CVE-2023-27532)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420) CVE-2024-40711 \[[Vulners](https://vulners.com/cve/CVE-2024-40711)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<12.2.0.334) CVE-2023-0669 \[[Vulners](https://vulners.com/cve/CVE-2023-0669)] - CVSS V3.1: *7.2*, - Vulners: Exploitation: True Soft: - fortra goanywhere_managed_file_transfer (<7.1.2) CVE-2025-33073 \[[Vulners](https://vulners.com/cve/CVE-2025-33073)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1507 (<10.0.10240.21034) - microsoft windows_10_1607 (<10.0.14393.8148) - microsoft windows_10_1809 (<10.0.17763.7434) - microsoft windows_10_21h2 (<10.0.19044.5965) ... 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1068, T1078, T1210 🧨IOCs: - File: 14 - Hash: 1 💽Software: MSSQL, PostgreSQL, Hyper-V, curl, PDQ Deploy, Windows Defender, FortiGate, PsExec, MOVEit, GoAnywhere, ... 🔢Algorithms: chacha20, md5 ⚙️Win Services: SQLAgent$VEEAMSQL2008R2, VeeamTransportSvc, BackupExecJobEngine, SQLSERVERAGENT, Symantec System Recovery 📜Programming Languages: powershell #threatreport: CVE-2026-44963 is described as a critical remote code execution vulnerability affecting Veeam Backup & Replication 12.x. The flaw reportedly involves insecure deserialization and allows a low-privileged, authenticated domain user to execute arbitrary code over the network against a domain-joined Veeam backup server. Successful exploitation can result in SYSTEM-level control of the server, making the vulnerability particularly significant because backup infrastructure often provides access to sensitive data and recovery operations. The report gives the vulnerability a CVSS score of 9.4 and compares it with earlier Veeam deserialization vulnerabilities, including CVE-2024-40711. The Lynx ransomware group allegedly claimed to use a private or improved version of the vulnerability that does not require domain credentials. An underground forum advertisement similarly claimed to offer an exploit that bypasses the June 2026 patch and achieves unauthenticated SYSTEM-level remote code execution. As of mid-August 2026, these claims had not been independently verified. The report notes that there was no public technical analysis, confirmed exploitation evidence, or vendor acknowledgment demonstrating a genuine unauthenticated bypass or residual vulnerability. The claims may therefore represent negotiation tactics intended to increase ransom demands or protect an alleged exploit. The report also connects the vulnerability to a private exploit advertised in 2025, assessing that it may have been an early version of, or the same underlying issue as, CVE-2026-44963. Veeam has historically been targeted by ransomware groups, including Akira, Fog, Cuba, and FIN7, because compromising backup servers enables attackers to disrupt recovery operations before deploying ransomware. Another major Veeam attack vector is CVE-2023-27532, which can expose credentials from the Veeam backup service and database. Attackers may use these credentials for initial access or lateral movement, including through post-compromise credential-dumping activity. Regardless of whether the alleged unauthenticated exploit exists, the authenticated RCE described for CVE-2026-44963 presents a serious risk wherever domain accounts or backup infrastructure are compromised.

    Post summary

    The report outlines a critical RCE flaw in Veeam Backup & Replication (CVE‑2026‑44963), providing technical details but no confirmed exploitation or PoC, while questioning the validity of unauthenticated bypass claims.

    00000241
    779 followersView on X
  • nksistemas@nksistemas
    General

    Alerta Crítica: Explotación de RCE en Veeam Backup &amp; Replication (CVE-2023-27532) https://nksistemas.com/alerta-critica-explotacion-de-rce-en-veeam-backup-replication-cve-2023-27532/

    Post summary

    The post flags CVE-2023-27532 as a critical RCE, but it offers no PoC details, exploit code, or mitigation information.

    0000066
    6.2K followersView on X
  • TheInsider-X.Com@TheInsider_x
    Patch

    Where AI FAILED: When trying to exploit CVE-2019-7192, CVE-2023-27532, and CVE-2024-40711 on PATCHED systems, the AI-generated code broke. It could not customize exploits for updated environments. Basic patching defeated the AI hacker.

    Post summary

    AI-generated exploit attempts for CVE-2019-7192, CVE-2023-27532, and CVE-2024-40711 failed against patched systems, showing that basic patching effectively mitigated these vulnerabilities.

    00000108
    7 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appveeamveeam_backup_\&_replication---
Appveeamveeam_backup_\&_replication11.0.1.1261--
Appveeamveeam_backup_\&_replication11.0.1.1261--
Appveeamveeam_backup_\&_replication11.0.1.1261--
Appveeamveeam_backup_\&_replication11.0.1.1261--
Appveeamveeam_backup_\&_replication12.0.0.1420--

Explore more