Critical Veeam Backup & Replication Vulnerability Lets Attackers Run Malicious Code
Key Takeaways Veeam has issued an urgent patch for multiple security vulnerabilities in its Backup & Replication software. The most critical flaw, CVE-2025-64393, enables remote code execution on...
Key Takeaways
- Veeam has issued an urgent patch for multiple security vulnerabilities in its Backup & Replication software.
- The most critical flaw, CVE-2025-64393, enables remote code execution on the Veeam Backup Server with low-privileged access.
- Another significant vulnerability, CVE-2025-64392, allows for cross-site scripting in Veeam Backup Enterprise Manager.
- Vulnerabilities impact various versions, including Veeam Backup & Replication 12.3.2.4854 and earlier, with some affecting version 13 builds.
- Admins must update to Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934) immediately to mitigate risks.
Veeam has released a critical update, Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934), to address four significant security vulnerabilities. These flaws range in severity, including a critical remote code execution vulnerability on the backup server and a cross-site scripting flaw that could allow attackers to run malicious scripts within an authenticated user’s browser.
Table Of Content
The update, made public on October 6, 2026, tackles issues with CVSS 4.0 scores from 4.8 to 9.4. The vulnerabilities encompass browser script execution, insecure deserialization, unauthorized access to sensitive configuration data, and the ability to read arbitrary files.
While the specific conditions for exploiting these weaknesses vary, several require only authenticated accounts with limited privileges, highlighting the importance of reviewing account permissions in affected environments.
Veeam Backup Enterprise Manager Vulnerability
A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2025-64392, impacts Veeam Backup Enterprise Manager. This flaw, rated medium severity with a CVSS score of 4.8, permits an attacker to execute arbitrary scripts in the browser of an authenticated portal user. Exploitation occurs if the user clicks a specially crafted malicious link.
Crucially, this vulnerability requires user interaction, distinguishing it from direct code execution on the backup server. Veeam’s advisory states that Enterprise Manager build 12.3.2.4854 and earlier version 12 builds are affected, while version 13 remains unaffected.
Veeam Backup & Replication Server Vulnerability
The most severe issue is CVE-2025-64393, categorized as critical with a CVSS score of 9.4. This vulnerability enables a low-privileged user, such as one assigned the Backup Viewer role, to achieve remote code execution on the Veeam Backup Server. This is accomplished through insecure deserialization of untrusted data received via the Mount Service.
The risk posed by this flaw is substantial because it does not require administrator privileges for exploitation, and Veeam’s CVSS vector indicates that user interaction is not necessary. Builds 12.3.2.4854 and earlier 12.3 builds are impacted, with the fix integrated into build 12.3.2.4934.
Another high-severity vulnerability, CVE-2026-58069, with a CVSS score of 8.3, allows an authenticated Veeam Cloud Connect tenant to read arbitrary files on the service provider host. Unlike the other vulnerabilities described in KB4934, this issue also affects specific version 13 builds, for which separate patches have been issued.
Finally, CVE-2026-93026, rated medium severity with a CVSS score of 6.1, allows an authenticated Backup Viewer user to modify or delete the Enterprise Manager master key. This user can also read or overwrite stored antivirus update credentials on the backup server.
Administrators can verify their installed build version by navigating to Help > About in the Veeam Backup & Replication Console’s Main Menu. Veeam strongly advises all affected version 12 deployments to upgrade to build 12.3.2.4934. The company warns that threat actors may reverse-engineer published patches to develop exploits for unpatched systems.
Beyond security fixes, the release notes also detail resolutions for issues such as Linux server re-addition failures due to missing SSH credentials and Windows Agent installation or upgrade problems on Windows 7 and Windows Server 2008 R2.
What You Should Do
- Immediately update Veeam Backup & Replication to version 12.3.2 P4 (build 12.3.2.4934) for all affected deployments.
- Check your current build version via the Veeam Backup & Replication Console (Main Menu > Help > About).
- For Veeam Cloud Connect tenants and service providers, ensure version 13 builds are also updated with their respective patches for CVE-2026-58069.
- Review and enforce the principle of least privilege for all Veeam accounts, especially those with Backup Viewer or low-privileged roles.
- Monitor Veeam’s official security advisories for any further updates or recommendations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.