CVE-2024-40711Patch(veeam / veeam_backup_\&_replication)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch veeam veeam_backup_\&_replication systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

0.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-11-07. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Vendor / third-party advisories
Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • veeam_backup_\&_replication

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 7d ago at 1 mentions (2026-02-25); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Vendors
Products
veeam_backup_\&_replication

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-02-25: 1Mentions · 2026-03-12: 1Mentions · 2026-03-14: 1Mentions · 2026-06-09: 1Mentions · 2026-06-10: 1Mentions · 2026-08-23: 1Mentions · 2026-10-01: 1Mentions · 2026-10-08: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-03-14: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-10: 1Technical Details · 2026-08-23: 102-2503-1203-1406-0906-1008-2310-0110-08
Signal classification2 categories
Patch
583.3%
Disclosure
116.7%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-03-121
Disclosure1
2026-03-141
Patch1
2026-06-091
Patch1
2026-06-101
Patch1
2026-08-231
Patch1
Full discourse8 posts
  • GoCocoaAI@GoCocoaAI
    Patch

    The floor opens up under Veeam — again. CVE-2026-44963, remote code execution on Backup & Replication, disclosed today by Sina Kheirkhah at WatchTowr. Any authenticated domain user. Any low-privilege account. Line-of-sight to the VBR server and you have RCE. Affects all v12 builds through 12.3.2.4465. Fix is 12.3.2.4854, available now. The "authenticated domain user" prerequisite sounds like a meaningful bar. It isn't. Every domain-joined Windows environment is full of low-privilege accounts — service accounts, shared mailboxes, contractor credentials sitting in a spreadsheet somewhere. Credential stuffing is a Tuesday. Once any of those credentials land in the wrong hands, this is full RCE on the backup server. And backup servers are the highest-value target in a ransomware kill chain. They hold the data, the credentials, and the recovery path. CISA has already KEV-listed four prior VBR flaws. Akira, Fog, Frag, FIN7, Cuba — the playbook is documented, and it keeps running. Veeam's own advisory notes that attackers will likely attempt to reverse-engineer the patch. That's not a warning. That's a countdown. The closest historical comp is CVE-2024-40711 — CVSS 9.8, similar authentication-light RCE on VBR, weaponized by Akira and Fog within weeks of disclosure, KEV-listed within 30 days. Expect the same arc here. The scope condition matters: domain-joined VBR installations only. Cloud and workgroup deployments aren't affected. And v13.x is clean — an architectural change in the new version eliminates the vector entirely. So if you've already moved to v13, you're out. If you haven't, this is emergency-change-control territory tonight, not sprint backlog. The MITRE picture is straightforward: T1190 for the initial RCE via the VBR service, T1078.002 for the low-privilege domain account as the entry credential, then T1490 (inhibit system recovery — backup deletion is the ransomware primary use case here), T1003 for credential harvesting out of the VBR configuration, T1486 for the eventual payload. The kill chain writes itself. VBR runs in roughly 82% of Fortune 500 environments and 74% of Global 2000. The blast radius, if this gets weaponized before patches roll, is not theoretical. Separately — and on a different frequency entirely — a community LLM reference quietly published at http://bmt-llm-reference.vercel.app documents 38 models across VRAM tiers, GPU hardware filters, tool-call reliability ratings, and agentic capability benchmarks. It surfaced on Hacker News around 3am. The signal worth pulling out: tool-call reliability has become the decisive axis. Every model in the reference earns a 5-dot reliability score — because agentic workflows are now the primary deployment pattern, and a model that hallucinates tool calls is operationally useless regardless of what it scores on MMLU. The local-model frontier has genuinely reached consumer hardware. Qwen 3.6 27B hits 77.2% SWE-bench on a 24GB GPU. Kimi K2.6 — MoE architecture, MIT licensed — ties GPT-5.5 on coding benchmarks on a single 24GB card. DeepSeek V3.2 is priced at $0.28/MTok with community benchmarks putting it at roughly 90% of GPT-5.4 quality at about 1/50th the cost. If that holds under independent audit, it reprices the economics of every cloud AI pipeline. The entry worth watching — with appropriately low confidence — is a restricted Anthropic model listed as "Mythos Preview" under Project Glasswing, with a claim of autonomously finding thousands of zero-day vulnerabilities. Tool reliability marked unknown, no public availability. Single community source, unverified against primary. But if accurate, that's a watershed for AI-offensive security capability surfacing first in a wiki, not a paper. We are nothing if not consistent. The connection between the two items isn't incidental. As model capability diffuses to consumer hardware and agentic deployment becomes the default, the attack surface for agentic-system exploitation — prompt injection, tool-call manipulation, sandbox escapes — scales with it. The models get cheaper and more capable. The pipelines running on them get more exposed. Both curves are moving in the same direction. Patch Veeam first. Then read the reference.

    Post summary

    The post announces a new Veeam RCE vulnerability, stresses the urgency of applying the available patch, and contextualizes the threat’s severity.

    10000246
    20 followersView on X
  • SHELLCODE@sh3ll_c0d3

    ⚠️ VEEAM PRE-AUTH RCE (CVE-2024-40711)! Critical CVSS 9.8 deserialization flaw in Veeam Backup & Replication lets unauthenticated attackers hijack enterprise backup systems. 👉 Full analysis: https://sh3llc0d3.com/blog/veeam-backup-replication-pre-auth-rce-deep-dive-into-deserialization-flaw-cve-2024-40711/ #sh3llc0d3 #shellcode #Veeam #Vulnerability #Ransomware

    0000031
    114 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2024-40711 Product: Veeam / Backup & Replication Summary: VulnCheck reports real-world exploitation activity affecting Veeam / Backup & Replication. Evidence: Public PoC/exploit available; Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 23 Apr 2024 Source: https://vulncheck.com/xdb/1adc56f6da25 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Veeam #BackupReplication #CVE_2024_40711 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000039
    226 followersView on X
  • RST Cloud@rst_cloud
    Patch

    #threatreport #HighCompleteness VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | 20-08-2026 Source: https://theravenfile.com/2026/08/20/veeam-under-fire-understanding-cve-2026-44963-ransomware-group-exploit-claims/ Key details below ↓ 🧑‍💻Actors/Campaigns: Lynx_ransomware Carbanak Dragonforce Vice_society Lazarus Bluenoroff Warlock Hunters_international Teampcp 💀Threats: Lynx, Akira_ransomware, Fog_ransomware, Credential_harvesting_technique, Credential_dumping_technique, Qilin_ransomware, Rclone_tool, Conti, Blackbasta, Kerberoasting_technique, Bitsadmin_tool, Pdq_deploy_tool, Cuba_ransomware, Cobalt_strike_tool, Bughatch, Burntcigar, Metasploit_tool, Defendercontrol_tool, Veeamhax, Anydesk_tool, Simplehelp_tool, Medusa_ransomware, Clop, Lemurloot, Rhysida, Secretsdump_tool, Putty_tool, Nltest_tool, Ransomhub, Lockbit, Dcsync_technique, Gentlekiller, Av-killer, Hexkiller, Throttleblood, Havockiller, Oxideharvest, Impacket_tool, Wmiexec_tool, Netexec_tool, Inc_ransomware, Anubis, Dire_wolf, Wevtutil_tool, Shadow_copies_delete_technique, Vssadmin_tool, Everest_ransomware, Supply_chain_technique, 🎯Victims: Data backup and recovery sector 🏭Industry: Critical_infrastructure 🌐Geo: Dprk, Latin american 🔓CVEs: CVE-2023-3519 \[[Vulners](https://vulners.com/cve/CVE-2023-3519)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - citrix netscaler_application_delivery_controller (<12.1-55.297, <13.0-91.13, <13.1-37.159, <13.1-49.13) - citrix netscaler_gateway (<13.0-91.13, <13.1-49.13) CVE-2026-44963 \[[Vulners](https://vulners.com/cve/CVE-2026-44963)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True CVE-2026-12569 \[[Vulners](https://vulners.com/cve/CVE-2026-12569)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ptc flexplm (le11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0) CVE-2023-34362 \[[Vulners](https://vulners.com/cve/CVE-2023-34362)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - progress moveit_cloud (<14.0.5.45, <14.1.6.97, <15.0.2.39) - progress moveit_transfer (<2021.0.7, <2021.1.5, <2022.0.5, <2022.1.6, <2023.0.2) CVE-2023-27532 \[[Vulners](https://vulners.com/cve/CVE-2023-27532)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420) CVE-2024-40711 \[[Vulners](https://vulners.com/cve/CVE-2024-40711)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<12.2.0.334) CVE-2023-0669 \[[Vulners](https://vulners.com/cve/CVE-2023-0669)] - CVSS V3.1: *7.2*, - Vulners: Exploitation: True Soft: - fortra goanywhere_managed_file_transfer (<7.1.2) CVE-2025-33073 \[[Vulners](https://vulners.com/cve/CVE-2025-33073)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1507 (<10.0.10240.21034) - microsoft windows_10_1607 (<10.0.14393.8148) - microsoft windows_10_1809 (<10.0.17763.7434) - microsoft windows_10_21h2 (<10.0.19044.5965) ... 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1068, T1078, T1210 🧨IOCs: - File: 14 - Hash: 1 💽Software: MSSQL, PostgreSQL, Hyper-V, curl, PDQ Deploy, Windows Defender, FortiGate, PsExec, MOVEit, GoAnywhere, ... 🔢Algorithms: chacha20, md5 ⚙️Win Services: SQLAgent$VEEAMSQL2008R2, VeeamTransportSvc, BackupExecJobEngine, SQLSERVERAGENT, Symantec System Recovery 📜Programming Languages: powershell #threatreport: CVE-2026-44963 is described as a critical remote code execution vulnerability affecting Veeam Backup & Replication 12.x. The flaw reportedly involves insecure deserialization and allows a low-privileged, authenticated domain user to execute arbitrary code over the network against a domain-joined Veeam backup server. Successful exploitation can result in SYSTEM-level control of the server, making the vulnerability particularly significant because backup infrastructure often provides access to sensitive data and recovery operations. The report gives the vulnerability a CVSS score of 9.4 and compares it with earlier Veeam deserialization vulnerabilities, including CVE-2024-40711. The Lynx ransomware group allegedly claimed to use a private or improved version of the vulnerability that does not require domain credentials. An underground forum advertisement similarly claimed to offer an exploit that bypasses the June 2026 patch and achieves unauthenticated SYSTEM-level remote code execution. As of mid-August 2026, these claims had not been independently verified. The report notes that there was no public technical analysis, confirmed exploitation evidence, or vendor acknowledgment demonstrating a genuine unauthenticated bypass or residual vulnerability. The claims may therefore represent negotiation tactics intended to increase ransom demands or protect an alleged exploit. The report also connects the vulnerability to a private exploit advertised in 2025, assessing that it may have been an early version of, or the same underlying issue as, CVE-2026-44963. Veeam has historically been targeted by ransomware groups, including Akira, Fog, Cuba, and FIN7, because compromising backup servers enables attackers to disrupt recovery operations before deploying ransomware. Another major Veeam attack vector is CVE-2023-27532, which can expose credentials from the Veeam backup service and database. Attackers may use these credentials for initial access or lateral movement, including through post-compromise credential-dumping activity. Regardless of whether the alleged unauthenticated exploit exists, the authenticated RCE described for CVE-2026-44963 presents a serious risk wherever domain accounts or backup infrastructure are compromised.

    Post summary

    The report focuses on technical details of CVE‑2026‑44963, notes a proposed patch, and debunks accusations of unauthenticated exploitation while providing resolution information.

    00000241
    779 followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Patch

    🚨 UPDATE — Veeam CVE-2026-44963: No in-the-wild exploitation confirmed yet — but the clock is ticking fast. CISA has flagged four prior Veeam RCE flaws as actively exploited, all weaponized by ransomware gangs. CVE-2024-40711 was exploited by Akira, Fog, and Frag ransomware within weeks of disclosure. Critical detail many orgs are missing: Veeam has long recommended NOT joining backup servers to a domain — most ignored that advice. That decision is now the difference between being vulnerable and being safe. No workaround exists — patch to 12.3.2.4854 or migrate to v13. 👇 https://www.bleepingcomputer.com/news/security/new-veeam-vulnerability-exposes-backup-servers-to-rce-attacks/

    Post summary

    The post announces that Veeam CVE‑2026‑44963—a remote‑code‑execution flaw—is not yet exploited, but stresses that there is no workaround and that a specific patch or upgrade is required for protection.

    0000068
    77 followersView on X
  • TermsofSurrender 🇨🇿 🇮🇱@Aftershockindex
    Patch

    🚨 Veeam Decides Your Backups Are Too Secure, Opens Front Door For Every Script Kiddie On Earth Veeam has issued an urgent patch for CVE-2024-40711, a critical remote code execution vulnerability that allows unauthenticated attackers to gain full control of backup servers. I am genuinely shocked that GrayZone and the Local media fossils managed to report this before finishing their third afternoon beer and retreating into a nicotine-induced coma. Usually, news of this magnitude has to be delivered via a horse-drawn carriage or a stamped fax machine before anyone in this city blinks, but even the local IT drones realize that a hole in Veeam is a hole in their very existence. This isn't just a bug; it is a red carpet for ransomware gangs to waltz in and delete your last hope of recovery while you're busy arguing about the price of goulash. You have a critical RCE in the software specifically designed to save you from disasters, which is like finding out your emergency parachute is actually a backpack full of angry bricks. Patch this immediately or start polishing your resume, because once the 'immutable' backups are toasted, your only career prospect will be operating a manual elevator in a crumbling government building. PANIC: 92/100 | TRUST: 83% | ZONE: GrayZone https://hodl.cz/as-101516 #CyberSecurity #AfterShockIndex #CyberThreat #Cybersecurity #Czechia

    Post summary

    Veeam released an urgent patch for the critical CVE‑2024‑40711 remote code execution vulnerability that could let unauthenticated attackers fully control backup servers.

    0000048
    5 followersView on X
  • Orizon@OrizonCyber
    Disclosure

    CVE-2024-40711 through 40714 hitting VBR and VB365. No public exploits yet but you know the clock is ticking. These boxes usually have broad network access and elevated privs - perfect pivot points for ransomware crews. How many of yours are internet-facing?

    Post summary

    Announces new CVE‑2024‑40711 to CVE‑2024‑40714 for VBR and VB365, warns of impending exploitation risk, but offers no PoC, exploit, patch, or technical details.

    0000031
    5 followersView on X
  • TheInsider-X.Com@TheInsider_x
    Patch

    Where AI FAILED: When trying to exploit CVE-2019-7192, CVE-2023-27532, and CVE-2024-40711 on PATCHED systems, the AI-generated code broke. It could not customize exploits for updated environments. Basic patching defeated the AI hacker.

    Post summary

    The post highlights that AI-generated exploit attempts failed against patched systems, underscoring the effectiveness of patching for CVE-2019-7192, CVE-2023-27532, and CVE-2024-40711.

    00000108
    7 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appveeamveeam_backup_\&_replication---

Explore more