Skip to content
TrustList
News

Veeam fixes critical remote code flaw in Backup & Replication 12

Editorial

By TrustList Editorial

Version 13 is not affected, and Veeam lists no workaround. Singapore's cyber agency repeated the warning on 9 October, and version 12 reaches end of support on 28 February 2027.

About Veeam fixes critical remote code flaw in Backup & Replication 12

Veeam fixes critical remote code flaw in Backup & Replication 12

6 October 2026: Veeam has patched CVE-2025-64393, a critical flaw (CVSS v4.0 score 9.4) that lets a user holding only the Backup Viewer role run code on the backup server, and has shipped the fix in Backup & Replication 12.3.2 P4. Singapore's Cyber Security Agency published its own alert on 9 October with two words of advice: patch immediately.

Not yet independently verified. Veeam's page does not say whether any of the three flaws is being exploited. The release date of build 12.3.2.4934 is not given separately from the article date. We will update this when it can be confirmed, and remove this note.

The bug is an insecure deserialisation of data received through the Mount Service. Because the Backup Viewer role is meant for low-privileged staff such as help-desk or audit users, the flaw turns a read-oriented account into a route to the server that holds every backup and the credentials used to reach production systems. Veeam credits the report to HackerOne.

Which builds are affected

Veeam says all three flaws in the bulletin affect build 12.3.2.4854 (12.3.2 P3) and earlier version 12 builds. Version 13 is not affected. The fixed build is 12.3.2.4934, delivered as 12.3.2 P4.

  • CVE-2025-64393, critical, CVSS 9.4: remote code execution as described above.
  • CVE-2026-93026, medium, CVSS 6.1: a Backup Viewer can modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials.
  • CVE-2025-64392, medium, CVSS 4.8: reflected cross-site scripting in Backup Enterprise Manager, triggered when an authenticated portal user opens a crafted link.

Veeam lists no workaround. The only remedy in the bulletin is to install the patch. The company also warns that attackers are likely to reverse-engineer patches to target systems that have not been updated, and the bulletin does not say whether any of the flaws has been used in an attack.

Version 12 is near the end of its support

The same page states that version 12 reaches end of support on 28 February 2027. A team that applies P4 now still has under five months before it must move to version 13, which is outside the affected range. Anyone planning that upgrade anyway has a reason to bring it forward.

Until the patch is installed, check who holds the Backup Viewer role and remove it from accounts that do not need it. Our backup software category lists four products and our server backup software category lists 21.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy