Veeam fixes critical remote code flaw in Backup & Replication 12
EditorialBy TrustList Editorial
Version 13 is not affected, and Veeam lists no workaround. Singapore's cyber agency repeated the warning on 9 October, and version 12 reaches end of support on 28 February 2027.
- Singapore
- Cybersecurity
- Vulnerability Management
- Backup
- +1 more
About Veeam fixes critical remote code flaw in Backup & Replication 12
Veeam fixes critical remote code flaw in Backup & Replication 12
6 October 2026: Veeam has patched CVE-2025-64393, a critical flaw (CVSS v4.0 score 9.4) that lets a user holding only the Backup Viewer role run code on the backup server, and has shipped the fix in Backup & Replication 12.3.2 P4. Singapore's Cyber Security Agency published its own alert on 9 October with two words of advice: patch immediately.
Not yet independently verified. Veeam's page does not say whether any of the three flaws is being exploited. The release date of build 12.3.2.4934 is not given separately from the article date. We will update this when it can be confirmed, and remove this note.
The bug is an insecure deserialisation of data received through the Mount Service. Because the Backup Viewer role is meant for low-privileged staff such as help-desk or audit users, the flaw turns a read-oriented account into a route to the server that holds every backup and the credentials used to reach production systems. Veeam credits the report to HackerOne.
Which builds are affected
Veeam says all three flaws in the bulletin affect build 12.3.2.4854 (12.3.2 P3) and earlier version 12 builds. Version 13 is not affected. The fixed build is 12.3.2.4934, delivered as 12.3.2 P4.
- CVE-2025-64393, critical, CVSS 9.4: remote code execution as described above.
- CVE-2026-93026, medium, CVSS 6.1: a Backup Viewer can modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials.
- CVE-2025-64392, medium, CVSS 4.8: reflected cross-site scripting in Backup Enterprise Manager, triggered when an authenticated portal user opens a crafted link.
Veeam lists no workaround. The only remedy in the bulletin is to install the patch. The company also warns that attackers are likely to reverse-engineer patches to target systems that have not been updated, and the bulletin does not say whether any of the flaws has been used in an attack.
Version 12 is near the end of its support
The same page states that version 12 reaches end of support on 28 February 2027. A team that applies P4 now still has under five months before it must move to version 13, which is outside the affected range. Anyone planning that upgrade anyway has a reason to bring it forward.
Until the patch is installed, check who holds the Backup Viewer role and remove it from accounts that do not need it. Our backup software category lists four products and our server backup software category lists 21.
Sources
Categories & features
- Singapore
- Cybersecurity
- Vulnerability Management
- Backup
- Backup and Recovery
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More SingaporeThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.