Veeam has addressed four serious security vulnerabilities in its Backup & Replication platform, releasing version 12.3.2 P4 (build 12.3.2.4934) on October 6, 2026. These include a remote code execution exploit on backup servers and a cross-site scripting issue in Enterprise Manager, among others. The flaws carry CVSS scores from 4.8 to 9.4, spanning medium to critical severity. All users running affected build versions are urged to upgrade without delay.
Main Threats at a Glance
The most severe vulnerability, tracked as CVE-2025-64393, allows a low-privileged user with the Backup Viewer role to trigger remote code execution through insecure deserialization via the Mount Service—administrative access or high privilege roles are not required. This bug affects versions ≤12.3.2.4854 and is resolved in build 12.3.2.4934.
Another serious issue, CVE-2026-58069, rated high (CVSS 8.3), permits any authenticated Veeam Cloud Connect tenant to read arbitrary files from the host machine. This also affects some version 13 builds, making timely patching essential.
A medium-severity reflected cross-site scripting vulnerability (CVE-2025-64392) in Enterprise Manager affects portal users who click specially crafted links—it requires authentication and user interaction. Version 13 is not impacted; earlier 12 builds are vulnerable.
Lastly, CVE-2026-93026 (medium, CVSS 6.1) allows Backup Viewer users to manipulate or delete the Enterprise Manager master key and access or overwrite stored antivirus update credentials. The flaw also affects builds up to 12.3.2.4854.
What’s Fixed & What To Do
All four vulnerabilities are resolved in build 12.3.2.4934. Administrators should verify their current version via the Help > Aboutmenu in the Veeam Backup & Replication Console. Deploying the patch is urgent—once security patches are made public, attackers often reverse-engineer them to target unpatched systems.
The update also addresses several operational bugs: Linux server reconnection errors caused by missing SSH credentials, and installation or upgrade failures for Windows agents on older systems like Windows 7 and Windows Server 2008 R2. These fixes are part of the same release.
Deployments with limited-privilege or tenant-level access are at risk in multiple cases, especially since some flaws don’t require admin access or any user interaction. If you’re running version 12 build 12.3.2.4854 or below—or specified version 13 builds—you should plan patching immediately.
In operating environments with Veeam Enterprise Manager exposed, cross-site scripting could allow attackers to embed malicious scripts that execute in authenticated users’ browsers. In contrast, the remote code execution vulnerability poses even higher risk—it can let an attacker take control of the backup server without needing privileged credentials.
Additional changes in the patch release include fixes for SSH credential mishandling on Linux and Agent upgrade issues on older Windows versions, enhancing both security and stability for mixed-platform deployments.
Why this matters:Veeam is widely used in enterprise data protection environments, and backup servers often have privileged access across networks. A breach here can be catastrophic—data theft, ransomware propagation, or persistent access. Because many affected flaws require only minimal or low-privilege access and no user interaction, the attack surface is larger than typical. Expect threat actors to attempt exploits now that patches are published.
What to watch:Monitor for reports of exploitation in the wild, prioritize patching by risk (especially public-facing systems), review role assignments for Backup Viewer credentials, and verify version alignment to avoid legacy exposure.