Veeam released security updates to address a critical vulnerability that lets low-privileged users execute remote code on Veeam Backup Servers.
Identified as CVE-2025-64393, this flaw has a CVSS v4.0 score of 9.4 and was resolved in Veeam Backup & Replication version 12.3.2 P4, build 12.3.2.4934, released on October 6, 2026.
The vulnerability affects build 12.3.2.4854 and all earlier builds in version 12. Veeam has specifically stated that version 13 builds are not affected, making accurate version identification crucial for assessing exposure across backup environments.
According to Veeam’s advisory, exploitation of this vulnerability requires an authenticated account assigned the Backup Viewer role. The issue arises from the insecure deserialization of untrusted data processed through the Mount Service, allowing a low-privileged user to execute remote code on the backup server.
The published CVSS vector indicates a network-accessible attack path, low attack complexity, low privileges, and no required user interaction.
It also highlights the high impact on confidentiality, integrity, and availability for both the vulnerable system and subsequent systems. These characteristics contribute to the critical severity rating, despite the authentication requirement.
Veeam credits the initial report to HackerOne but does not provide exploit payloads, technical reproduction steps, or the specific execution account in their advisory.
The disclosure also does not confirm whether exploitation has occurred in the wild. However, these omissions should not be interpreted as a reassurance that affected installations are safe.
The October update also addresses three additional security issues related to Cloud Connect, Enterprise Manager, and sensitive backup server data. All severity ratings in the release notes use CVSS v4.0.
Administrators can check their installed build by navigating to the console’s main menu under Help > About. Veeam offers patch ISO and EXE packages for supported existing 12.3.2 builds; however, earlier releases, including versions 12.3.0 and 12.3.1, require the full installation ISO to upgrade.
If Enterprise Manager is deployed, Veeam advises customers to update that component before proceeding with Backup & Replication. A reboot may be necessary after the update.
The vendor urges prompt patching, as attackers could potentially reverse-engineer the disclosed fixes. Customers are also reminded that version 12 will reach its end of support on February 28, 2027.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…