Critical Vulnerabilities in Veeam Backup & Replication Expose Servers to RCE Attacks
Mar 12, 2026 // 21:00 - Lina Schonbein


Veeam has issued an urgent warning regarding critical vulnerabilities in its Veeam Backup & Replication (VBR) software that could allow unauthenticated attackers to achieve remote code execution (RCE) on backup servers. 

High-Risk Vulnerabilities

  • CVE-2024-40711 (CVSS 9.8): The most severe flaw allows an unauthenticated attacker to gain full control of the backup server. This is particularly dangerous as backup servers are high-priority targets for ransomware groups looking to delete recovery points before encrypting data.
  • CVE-2024-40713: A low-privileged user can exploit this to gain administrative access, potentially leading to data exfiltration or system compromise.
  • CVE-2024-40710: This vulnerability allows for remote code execution via a flaw in the Veeam backup service. 

Critical Impact

Backup infrastructure is a “crown jewel” for cybercriminals. Attackers frequently use these types of flaws to: 

  1. Neutralize Backups: Ensure the victim cannot restore their systems.
  2. Exfiltrate Data: Steal sensitive backups for double-extortion.
  3. Lateral Movement: Use the backup server’s high-level permissions to pivot into the rest of the corporate network. 

Mitigation Steps

Veeam has released patches for these vulnerabilities. Users are strongly advised to update to Veeam Backup & Replication version 12.2 or later immediately. 

Additionally, security experts recommend ensuring that backup servers are not exposed to the public internet and are protected by Multi-Factor Authentication (MFA).

#attacks  #backup  #critical  #expose  #news  #rce  #replication  #servers  #veeam  #vulnerabilities   —   News