TL;DR
Veeam has fixed three flaws in Backup & Replication version 12, led by CVE-2025-64393. This critical Veeam Backup vulnerability scores 9.4 on CVSS 4.0 and lets a low-privileged user run code on the backup server. The fixes ship in build 12.3.2.4934, known as 12.3.2 P4.
CISA KEV isn't the only exploit signal for Veeam CVEs. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy It Matters
Backup servers hold the copies that companies need to recover from ransomware. As a result, attackers who control them can wipe or tamper with recovery data. A remote code execution bug on that server is a serious risk. That makes this Veeam Backup vulnerability worth patching ahead of routine updates.
All three flaws came in through HackerOne. Veeam’s advisory does not report exploitation in the wild, and no public proof-of-concept has been confirmed.
How the Attacks Work
Critical RCE (CVE-2025-64393)
Veeam says the flaw allows “a low-privileged user with the Backup Viewer role to perform remote code execution (RCE) on the Veeam Backup Server.” It stems from “insecure deserialization of untrusted data received via the Mount Service.”
Other Flaws
CVE-2026-93026 (CVSS 6.1) also targets Backup Viewer accounts. It lets them “modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials.” Meanwhile, CVE-2025-64392 (CVSS 4.8) is a reflected XSS bug in Veeam Backup Enterprise Manager. It runs script when a logged-in user opens a crafted link.
Affected Versions
The Veeam Backup vulnerability affects build 12.3.2.4854 and all earlier version 12 builds. Notably, version 13 is not affected.
Patch and Mitigation Steps
Upgrade to Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934) or move to version 13. In addition, review who holds the Backup Viewer role, since the two most serious bugs start there.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!