Veeam Backup & Replication Patched for Critical RCE and Other Flaws
Veeam Backup & Replication 12.3.2 P4 addresses four vulnerabilities, including a critical RCE flaw via insecure deserialization and an XSS vulnerability in Enterprise Manager.

Veeam has issued an update, Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934), to resolve four security vulnerabilities affecting its backup solutions. The patches address issues ranging in severity, with the most critical allowing for remote code execution (RCE) on the backup server.
The most severe vulnerability, tracked as CVE-2025-64393, carries a critical CVSS score of 9.4. This flaw stems from insecure deserialization within the Mount Service and can be exploited by a low-privileged user with the Backup Viewer role. Crucially, exploitation does not require administrator privileges and does not necessitate user interaction, posing a significant risk to backup server integrity.
Another notable vulnerability, CVE-2025-64392, is a reflected cross-site scripting (XSS) flaw affecting Veeam Backup Enterprise Manager. With a CVSS score of 4.8, this vulnerability allows an attacker to execute malicious scripts in the browser of an authenticated user by tricking them into clicking a crafted link. This particular issue affects Enterprise Manager build 12.3.2.4854 and earlier version 12 builds, with version 13 remaining unaffected.
Beyond these, two other vulnerabilities have been patched. CVE-2026-58069, rated high with a CVSS score of 8.3, permits an authenticated Veeam Cloud Connect tenant to read arbitrary files on the service provider's host. This vulnerability affects specific version 13 builds as well, with separate fixes provided. Additionally, CVE-2026-93026, a medium-severity flaw (CVSS 6.1), allows an authenticated Backup Viewer user to modify or delete the Enterprise Manager master key and read or overwrite antivirus update credentials stored on the backup server.
Veeam has emphasized the importance of applying these patches promptly, warning that attackers may attempt to reverse-engineer patches to target unpatched systems. Administrators can verify their installed build through the Veeam Backup & Replication Console's Help > About section.
The update also includes fixes for other issues, such as failures in re-adding Linux servers due to missing SSH credentials and problems with Windows Agent installations or upgrades on older Windows operating systems like Windows 7 and Windows Server 2008 R2.
These vulnerabilities highlight the ongoing need for robust security practices in backup and disaster recovery solutions, as compromised backup systems can lead to significant data loss and operational disruption. The range of vulnerabilities, from RCE to data access and script injection, underscores the multifaceted threats faced by organizations relying on these critical infrastructure components.