Veeam Patches Critical Vulnerabilities in Backup & Replication Software
Veeam has released Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934) to address four security vulnerabilities, including a critical remote code execution (RCE) flaw and a reflected cross-site scripting (XSS) issue. The update, issued on October 6, 2026, mitigates risks with CVSS 4.0 scores ranging from 4.8 to 9.4, affecting various components of the backup platform.
Key Vulnerabilities Fixed
-
CVE-2025-64392 (CVSS 4.8 – Medium)
- A reflected XSS vulnerability in Veeam Backup Enterprise Manager allows attackers to execute malicious scripts in the browser of an authenticated user who clicks a crafted link.
- Affects build 12.3.2.4854 and earlier version 12 releases; version 13 is unaffected.
-
CVE-2025-64393 (CVSS 9.4 – Critical)
- A low-privileged user with the Backup Viewer role can exploit insecure deserialization in the Mount Service to achieve RCE on the Veeam Backup Server.
- Exploitation does not require admin privileges or user interaction, posing a severe risk.
- Affects build 12.3.2.4854 and earlier 12.3 builds; patched in 12.3.2.4934.
-
CVE-2026-58069 (CVSS 8.3 – High)
- An authenticated Veeam Cloud Connect tenant can read arbitrary files on the service provider host.
- Also impacts certain version 13 builds, requiring separate fixes.
-
CVE-2026-93026 (CVSS 6.1 – Medium)
- An authenticated Backup Viewer can modify or delete the Enterprise Manager master key and access or overwrite antivirus update credentials.
Affected Versions & Mitigation
- Version 12 deployments should upgrade to build 12.3.2.4934.
- Version 13 users must apply separate patches for CVE-2026-58069.
- Veeam warns that unpatched systems may be targeted as attackers reverse-engineer fixes.
The update also resolves Linux server readdition failures and Windows Agent installation issues on legacy systems (Windows 7/Server 2008 R2). Administrators can verify their build via the Veeam Backup & Replication Console under Help > About.
Source: https://cybersecuritynews.com/veeam-backup-and-replication-vulnerability/
Veeam TPRM report: https://www.rankiteo.com/company/veeam-software
"id": "vee1791361423",
"linkid": "veeam-software",
"type": "Vulnerability",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of Veeam Backup & '
'Replication 12 and 13 (specific '
'builds)',
'industry': 'Data Backup and Recovery Software',
'name': 'Veeam',
'type': 'Company'}],
'attack_vector': ['Exploitation of insecure deserialization',
'Crafted link for XSS',
'Authenticated low-privilege access'],
'customer_advisories': 'Users of affected versions urged to upgrade to '
'patched builds',
'data_breach': {'sensitivity_of_data': 'High (backup and system credentials)',
'type_of_data_compromised': ['Arbitrary files',
'Master key',
'Credentials']},
'date_publicly_disclosed': '2026-10-06',
'date_resolved': '2026-10-06',
'description': 'Veeam has released Veeam Backup & Replication 12.3.2 P4 '
'(build 12.3.2.4934) to address four security vulnerabilities, '
'including a critical remote code execution (RCE) flaw and a '
'reflected cross-site scripting (XSS) issue. The update '
'mitigates risks with CVSS 4.0 scores ranging from 4.8 to 9.4, '
'affecting various components of the backup platform.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'unpatched vulnerabilities',
'data_compromised': ['Arbitrary files on service provider host',
'Enterprise Manager master key',
'Antivirus update credentials'],
'operational_impact': ['Potential unauthorized access to backup '
'systems',
'Risk of data exfiltration or modification'],
'systems_affected': ['Veeam Backup & Replication',
'Veeam Backup Enterprise Manager',
'Veeam Cloud Connect']},
'post_incident_analysis': {'corrective_actions': ['Patch release',
'Enhanced privilege '
'restrictions',
'Improved input validation'],
'root_causes': ['Insecure deserialization',
'Lack of input validation for XSS',
'Insufficient access controls']},
'recommendations': ['Upgrade to the latest patched versions immediately',
'Monitor for signs of exploitation',
'Review and restrict low-privilege user access'],
'references': [{'source': 'Veeam Security Advisory'}],
'response': {'communication_strategy': 'Public disclosure of vulnerabilities '
'and patch availability',
'containment_measures': 'Release of patches (build 12.3.2.4934 '
'for version 12, separate patches for '
'version 13)',
'remediation_measures': ['Upgrade to patched versions',
'Verify build via Veeam Backup & '
'Replication Console']},
'stakeholder_advisories': 'Administrators advised to verify builds and apply '
'patches',
'title': 'Veeam Patches Critical Vulnerabilities in Backup & Replication '
'Software',
'type': ['Remote Code Execution (RCE)',
'Cross-Site Scripting (XSS)',
'Insecure Deserialization',
'Arbitrary File Read'],
'vulnerability_exploited': ['CVE-2025-64392',
'CVE-2025-64393',
'CVE-2026-58069',
'CVE-2026-93026']}