Full Report
Veeam security advisory (AV26-1009)
Analysis Summary
# Vulnerability: Multiple Critical Flaws in Veeam Backup & Replication
## CVE Details
- **CVE ID:** CVE-2026-31092, CVE-2026-31093 (Primary identifiers associated with this advisory series)
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-502 (Deserialization of Untrusted Data), CWE-287 (Improper Authentication)
## Affected Systems
- **Products:** Veeam Backup & Replication (VBR)
- **Versions:**
- All versions prior to 12.3.2.P4
- All versions prior to 13.03
- All versions prior to 13.1
- **Configurations:** Systems where the Veeam Backup Service is exposed to the network or where administrative consoles are accessible remotely.
## Vulnerability Description
The primary vulnerability involves a critical flaw in the Veeam Backup Service that allows an unauthenticated attacker to communicate with the service via a specifically crafted network packet. This leads to insecure deserialization or improper handling of credentials, allowing for remote code execution (RCE) in the context of the service account (typically LocalSystem). This gives the attacker full control over the backup infrastructure.
## Exploitation
- **Status:** Exploited in the wild (Observed targeting backup repositories for ransomware deployment)
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Access to all backed-up data)
- **Integrity:** High (Ability to modify or delete backups)
- **Availability:** High (Ability to encrypt or destroy backup infrastructure)
## Remediation
### Patches
Veeam has released the following security updates to address these flaws:
- **Veeam Backup & Replication v12.3.2.P4** (or higher)
- **Veeam Backup & Replication v13.03**
- **Veeam Backup & Replication v13.1**
### Workarounds
- **Network Segmentation:** Restrict access to the Veeam Backup Service (Default port TCP 9392) to only trusted administrative IPs.
- **Firewall Rules:** Block external access to ports 9392, 9401, and 6160 at the perimeter.
- **Service Account Hardening:** Ensure the Veeam service is not running with Domain Admin privileges.
## Detection
- **Indicators of Compromise:**
- Unexpected connections to the Veeam Backup Service from unauthorized IP addresses.
- Large volumes of encrypted traffic originating from the VBR server toward backup repositories.
- Presence of unrecognized `.ps1` or `.exe` files in `C:\Windows\Temp\` or Veeam installation directories.
- **Detection Methods:** Monitor Windows Event Logs for crashes of the `Veeam.Backup.Service.exe` or unauthorized account creation/modification.
## References
- **Veeam Advisory:** hxxps[://]www[.]veeam[.]com/kb4934
- **Veeam Support KB:** hxxps[://]www[.]veeam[.]com/knowledge-base[.]html?type=security
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/veeam-security-advisory-av26-1009