Disclosure
#threatreport #HighCompleteness
VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | 20-08-2026
Source: https://theravenfile.com/2026/08/20/veeam-under-fire-understanding-cve-2026-44963-ransomware-group-exploit-claims/
Key details below ↓
🧑💻Actors/Campaigns:
Lynx_ransomware
Carbanak
Dragonforce
Vice_society
Lazarus
Bluenoroff
Warlock
Hunters_international
Teampcp
💀Threats:
Lynx, Akira_ransomware, Fog_ransomware, Credential_harvesting_technique, Credential_dumping_technique, Qilin_ransomware, Rclone_tool, Conti, Blackbasta, Kerberoasting_technique, Bitsadmin_tool, Pdq_deploy_tool, Cuba_ransomware, Cobalt_strike_tool, Bughatch, Burntcigar, Metasploit_tool, Defendercontrol_tool, Veeamhax, Anydesk_tool, Simplehelp_tool, Medusa_ransomware, Clop, Lemurloot, Rhysida, Secretsdump_tool, Putty_tool, Nltest_tool, Ransomhub, Lockbit, Dcsync_technique, Gentlekiller, Av-killer, Hexkiller, Throttleblood, Havockiller, Oxideharvest, Impacket_tool, Wmiexec_tool, Netexec_tool, Inc_ransomware, Anubis, Dire_wolf, Wevtutil_tool, Shadow_copies_delete_technique, Vssadmin_tool, Everest_ransomware, Supply_chain_technique,
🎯Victims: Data backup and recovery sector
🏭Industry: Critical_infrastructure
🌐Geo: Dprk, Latin american
🔓CVEs: CVE-2023-3519 \[[Vulners](https://vulners.com/cve/CVE-2023-3519)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- citrix netscaler_application_delivery_controller (<12.1-55.297, <13.0-91.13, <13.1-37.159, <13.1-49.13)
- citrix netscaler_gateway (<13.0-91.13, <13.1-49.13)
CVE-2026-44963 \[[Vulners](https://vulners.com/cve/CVE-2026-44963)]
- CVSS V3.1: *9.4*,
- Vulners: Exploitation: True
CVE-2026-12569 \[[Vulners](https://vulners.com/cve/CVE-2026-12569)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- ptc flexplm (le11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0)
CVE-2023-34362 \[[Vulners](https://vulners.com/cve/CVE-2023-34362)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- progress moveit_cloud (<14.0.5.45, <14.1.6.97, <15.0.2.39)
- progress moveit_transfer (<2021.0.7, <2021.1.5, <2022.0.5, <2022.1.6, <2023.0.2)
CVE-2023-27532 \[[Vulners](https://vulners.com/cve/CVE-2023-27532)]
- CVSS V3.1: *7.5*,
- Vulners: Exploitation: True
Soft:
- veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420)
CVE-2024-40711 \[[Vulners](https://vulners.com/cve/CVE-2024-40711)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- veeam veeam_backup_\&_replication (<12.2.0.334)
CVE-2023-0669 \[[Vulners](https://vulners.com/cve/CVE-2023-0669)]
- CVSS V3.1: *7.2*,
- Vulners: Exploitation: True
Soft:
- fortra goanywhere_managed_file_transfer (<7.1.2)
CVE-2025-33073 \[[Vulners](https://vulners.com/cve/CVE-2025-33073)]
- CVSS V3.1: *8.8*,
- Vulners: Exploitation: True
Soft:
- microsoft windows_10_1507 (<10.0.10240.21034)
- microsoft windows_10_1607 (<10.0.14393.8148)
- microsoft windows_10_1809 (<10.0.17763.7434)
- microsoft windows_10_21h2 (<10.0.19044.5965)
...
📚TTPs:
⚔️Tactics: 3
🛠️Technics: 0
🤖LLM extracted TTPs:`
T1068, T1078, T1210
🧨IOCs:
- File: 14
- Hash: 1
💽Software: MSSQL, PostgreSQL, Hyper-V, curl, PDQ Deploy, Windows Defender, FortiGate, PsExec, MOVEit, GoAnywhere, ...
🔢Algorithms: chacha20, md5
⚙️Win Services: SQLAgent$VEEAMSQL2008R2, VeeamTransportSvc, BackupExecJobEngine, SQLSERVERAGENT, Symantec System Recovery
📜Programming Languages: powershell
#threatreport:
CVE-2026-44963 is described as a critical remote code execution vulnerability affecting Veeam Backup & Replication 12.x. The flaw reportedly involves insecure deserialization and allows a low-privileged, authenticated domain user to execute arbitrary code over the network against a domain-joined Veeam backup server. Successful exploitation can result in SYSTEM-level control of the server, making the vulnerability particularly significant because backup infrastructure often provides access to sensitive data and recovery operations. The report gives the vulnerability a CVSS score of 9.4 and compares it with earlier Veeam deserialization vulnerabilities, including CVE-2024-40711.
The Lynx ransomware group allegedly claimed to use a private or improved version of the vulnerability that does not require domain credentials. An underground forum advertisement similarly claimed to offer an exploit that bypasses the June 2026 patch and achieves unauthenticated SYSTEM-level remote code execution. As of mid-August 2026, these claims had not been independently verified. The report notes that there was no public technical analysis, confirmed exploitation evidence, or vendor acknowledgment demonstrating a genuine unauthenticated bypass or residual vulnerability. The claims may therefore represent negotiation tactics intended to increase ransom demands or protect an alleged exploit.
The report also connects the vulnerability to a private exploit advertised in 2025, assessing that it may have been an early version of, or the same underlying issue as, CVE-2026-44963. Veeam has historically been targeted by ransomware groups, including Akira, Fog, Cuba, and FIN7, because compromising backup servers enables attackers to disrupt recovery operations before deploying ransomware.
Another major Veeam attack vector is CVE-2023-27532, which can expose credentials from the Veeam backup service and database. Attackers may use these credentials for initial access or lateral movement, including through post-compromise credential-dumping activity. Regardless of whether the alleged unauthenticated exploit exists, the authenticated RCE described for CVE-2026-44963 presents a serious risk wherever domain accounts or backup infrastructure are compromised.
Post summary
The threat report provides technical details on Veeam’s CVE‑2026‑44963, notes a patch, and counters unverified unauthenticated exploitation claims, with no evidence of active attacks.