Cyber Security News

Critical Veeam Backup & Replication Flaw Allows Low-Privileged Users to Execute Remote Code

Veeam released security updates to address a critical vulnerability that lets low-privileged users execute remote code on Veeam Backup Servers.

Identified as CVE-2025-64393, this flaw has a CVSS v4.0 score of 9.4 and was resolved in Veeam Backup & Replication version 12.3.2 P4, build 12.3.2.4934, released on October 6, 2026.

The vulnerability affects build 12.3.2.4854 and all earlier builds in version 12. Veeam has specifically stated that version 13 builds are not affected, making accurate version identification crucial for assessing exposure across backup environments.

Critical Veeam Backup & Replication Flaw

According to Veeam’s advisory, exploitation of this vulnerability requires an authenticated account assigned the Backup Viewer role. The issue arises from the insecure deserialization of untrusted data processed through the Mount Service, allowing a low-privileged user to execute remote code on the backup server.

The published CVSS vector indicates a network-accessible attack path, low attack complexity, low privileges, and no required user interaction.

It also highlights the high impact on confidentiality, integrity, and availability for both the vulnerable system and subsequent systems. These characteristics contribute to the critical severity rating, despite the authentication requirement.

Veeam credits the initial report to HackerOne but does not provide exploit payloads, technical reproduction steps, or the specific execution account in their advisory.

The disclosure also does not confirm whether exploitation has occurred in the wild. However, these omissions should not be interpreted as a reassurance that affected installations are safe.

The October update also addresses three additional security issues related to Cloud Connect, Enterprise Manager, and sensitive backup server data. All severity ratings in the release notes use CVSS v4.0.

  • CVE-2026-58069: Rated High at 8.3, this vulnerability allows an authenticated Veeam Cloud Connect tenant to read arbitrary files on the service provider host, creating a separate risk for providers operating Cloud Connect infrastructure.
  • CVE-2025-64392: Rated Medium at 4.8, this vulnerability involves reflected cross-site scripting in Veeam Backup Enterprise Manager. An attacker can execute scripts in an authenticated portal user’s browser when the victim opens a specially crafted link.
  • CVE-2026-93026: Rated Medium at 6.1, this vulnerability allows a Backup Viewer to modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials on the backup server.

Administrators can check their installed build by navigating to the console’s main menu under Help > About. Veeam offers patch ISO and EXE packages for supported existing 12.3.2 builds; however, earlier releases, including versions 12.3.0 and 12.3.1, require the full installation ISO to upgrade.

If Enterprise Manager is deployed, Veeam advises customers to update that component before proceeding with Backup & Replication. A reboot may be necessary after the update.

The vendor urges prompt patching, as attackers could potentially reverse-engineer the disclosed fixes. Customers are also reminded that version 12 will reach its end of support on February 28, 2027.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago