Veeam Backup & Replication Vulnerabilities Enable RCE Attacks

Veeam Backup & Replication Vulnerabilities Enable RCE Attacks

First seen 7 Jan 2026, 16:46 UTC Heise.DeVeeamBleepingcomputerCyberscoopAha+2 82% similarity 45.3

Article Content

Browse articles
ThreatCluster

Veeam has issued security updates to address multiple vulnerabilities in its Backup & Replication software, including a critical remote code execution (RCE) flaw tracked as CVE-2025-59470. This vulnerability affects Veeam Backup & Replication version 13.0.1.180 and earlier, allowing Backup or Tape Operators to execute code remotely as the postgres user. A separate RCE vulnerability was also noted, allowing execution as root through a malicious backup configuration file.

ThreatCluster AI

Community

Browse all →