Skip to content
Critical Vulnerability in Veeam Backup Allows Remote Code Execution

Critical Vulnerability in Veeam Backup Allows Remote Code Execution

First seen 7 Oct 2026, 15:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 17:29 UTC
  • •CVE-2025-64393 allows remote code execution for low-privileged users in Veeam Backup.
  • •The flaw has a CVSS score of 9.4 and affects version 12.3.2.4854 and earlier builds.
  • •Veeam has released patches and confirmed that version 13 is not affected.

Veeam has released security updates for a critical vulnerability (CVE-2025-64393) in its Backup & Replication software, allowing low-privileged users to execute remote code on backup servers. This flaw, with a CVSS score of 9.4, affects version 12.3.2.4854 and earlier builds but is not present in version 13. Exploitation requires an authenticated account with the Backup Viewer role and involves insecure deserialization of untrusted data via the Mount Service. The vulnerability was reported through HackerOne, but there are no confirmations of exploitation in the wild. Additionally, three other vulnerabilities were addressed in the same update, with severity ratings ranging from medium to high. Administrators are advised to check their installed builds and apply the necessary updates promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
Veeam releases security update
Veeam released version 12.3.2 P4 (build 12.3.2.4934) to address multiple vulnerabilities, including CVE-2025-64393.
Veeam
2026-10-07
CVE-2025-64393 published
CVE-2025-64393, a critical vulnerability allowing remote code execution, was published with a CVSS score of 9.4.
Gbhackers
2026-10-07
CVE-2026-93026 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2025-64392 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-58069 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track CVE-2025-64392 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of Veeam are affected?
Versions 12.3.2.4854 and earlier builds of Veeam Backup & Replication are affected.
How critical is the vulnerability?
The vulnerability has a CVSS score of 9.4, classifying it as critical.
What should I do to protect my systems?
Update to Veeam Backup & Replication version 12.3.2 P4 or later to mitigate the risk.