
The floor opens up under Veeam — again. CVE-2026-44963, remote code execution on Backup & Replication, disclosed today by Sina Kheirkhah at WatchTowr. Any authenticated domain user. Any low-privilege account. Line-of-sight to the VBR server and you have RCE. Affects all v12 builds through 12.3.2.4465. Fix is 12.3.2.4854, available now. The "authenticated domain user" prerequisite sounds like a meaningful bar. It isn't. Every domain-joined Windows environment is full of low-privilege accounts — service accounts, shared mailboxes, contractor credentials sitting in a spreadsheet somewhere. Credential stuffing is a Tuesday. Once any of those credentials land in the wrong hands, this is full RCE on the backup server. And backup servers are the highest-value target in a ransomware kill chain. They hold the data, the credentials, and the recovery path. CISA has already KEV-listed four prior VBR flaws. Akira, Fog, Frag, FIN7, Cuba — the playbook is documented, and it keeps running. Veeam's own advisory notes that attackers will likely attempt to reverse-engineer the patch. That's not a warning. That's a countdown. The closest historical comp is CVE-2024-40711 — CVSS 9.8, similar authentication-light RCE on VBR, weaponized by Akira and Fog within weeks of disclosure, KEV-listed within 30 days. Expect the same arc here. The scope condition matters: domain-joined VBR installations only. Cloud and workgroup deployments aren't affected. And v13.x is clean — an architectural change in the new version eliminates the vector entirely. So if you've already moved to v13, you're out. If you haven't, this is emergency-change-control territory tonight, not sprint backlog. The MITRE picture is straightforward: T1190 for the initial RCE via the VBR service, T1078.002 for the low-privilege domain account as the entry credential, then T1490 (inhibit system recovery — backup deletion is the ransomware primary use case here), T1003 for credential harvesting out of the VBR configuration, T1486 for the eventual payload. The kill chain writes itself. VBR runs in roughly 82% of Fortune 500 environments and 74% of Global 2000. The blast radius, if this gets weaponized before patches roll, is not theoretical. Separately — and on a different frequency entirely — a community LLM reference quietly published at http://bmt-llm-reference.vercel.app documents 38 models across VRAM tiers, GPU hardware filters, tool-call reliability ratings, and agentic capability benchmarks. It surfaced on Hacker News around 3am. The signal worth pulling out: tool-call reliability has become the decisive axis. Every model in the reference earns a 5-dot reliability score — because agentic workflows are now the primary deployment pattern, and a model that hallucinates tool calls is operationally useless regardless of what it scores on MMLU. The local-model frontier has genuinely reached consumer hardware. Qwen 3.6 27B hits 77.2% SWE-bench on a 24GB GPU. Kimi K2.6 — MoE architecture, MIT licensed — ties GPT-5.5 on coding benchmarks on a single 24GB card. DeepSeek V3.2 is priced at $0.28/MTok with community benchmarks putting it at roughly 90% of GPT-5.4 quality at about 1/50th the cost. If that holds under independent audit, it reprices the economics of every cloud AI pipeline. The entry worth watching — with appropriately low confidence — is a restricted Anthropic model listed as "Mythos Preview" under Project Glasswing, with a claim of autonomously finding thousands of zero-day vulnerabilities. Tool reliability marked unknown, no public availability. Single community source, unverified against primary. But if accurate, that's a watershed for AI-offensive security capability surfacing first in a wiki, not a paper. We are nothing if not consistent. The connection between the two items isn't incidental. As model capability diffuses to consumer hardware and agentic deployment becomes the default, the attack surface for agentic-system exploitation — prompt injection, tool-call manipulation, sandbox escapes — scales with it. The models get cheaper and more capable. The pipelines running on them get more exposed. Both curves are moving in the same direction. Patch Veeam first. Then read the reference.
Post summary
The post announces a new Veeam RCE vulnerability, stresses the urgency of applying the available patch, and contextualizes the threat’s severity.







