T

Threats

Veeam Backup & Replication Remote Code Execution

Overview

Veeam's security advisory KB4934 covers one Critical and two Medium vulnerabilities. Organisations running affected version 12 builds should prioritise the vendor update. Exploitation prerequisites differ: the server-side flaws require the Backup Viewer role, while the Enterprise Manager cross-site scripting flaw requires an authenticated portal user to open a crafted link.


Affected Versions

Veeam Backup & Replication - CVE-2025-64393 and CVE-2026-93026

Veeam Backup Enterprise Manager - CVE-2025-64392

  • Affected: Veeam Backup Enterprise Manager, the Veeam Backup & Replication component, build 12.3.2.4854 and all earlier version 12 builds.

  • Fixed: Veeam Backup & Replication 12.3.2 P4, build 12.3.2.4934, including the Enterprise Manager component.

  • Not affected: Version 13 builds.

  • Source: Veeam KB4934: Enterprise Manager cross-site scripting advisory.


Vulnerability Breakdown

CVE-2025-64393 - Remote Code Execution Through Insecure Deserialisation

  • Severity: Critical

  • CVSS: 9.4, CVSS v4.0

  • Description: Insecure deserialisation of untrusted data received through the Mount Service allows remote code execution on the Veeam Backup Server.

  • Impact: An attacker can execute code on the backup server, threatening the confidentiality, integrity and availability of the backup environment.

  • Conditions: The attacker requires a low-privileged account with the Backup Viewer role. The vendor's CVSS vector indicates no user interaction is required.

  • Source: Veeam KB4934: CVE-2025-64393 details.

CVE-2026-93026 - Sensitive Key and Credential Access

  • Severity: Medium

  • CVSS: 6.1, CVSS v4.0

  • Description: An authenticated Backup Viewer can modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials on the Veeam Backup Server.

  • Impact: Unauthorised alteration or deletion of sensitive key material and disclosure or modification of stored credentials.

  • Conditions: An authenticated account with the Backup Viewer role is required.

  • Source: Veeam KB4934: CVE-2026-93026 details.

CVE-2025-64392 - Reflected Cross-Site Scripting

  • Severity: Medium

  • CVSS: 4.8, CVSS v4.0

  • Description: A reflected cross-site scripting flaw in Veeam Backup Enterprise Manager allows an attacker to execute script in an authenticated portal user's browser.

  • Impact: Unauthorised script execution in the affected user's browser.

  • Conditions: An authenticated portal user must open a crafted link.

  • Source: Veeam KB4934: CVE-2025-64392 details.


Mitigation

  • Update affected version 12 deployments to 12.3.2 P4, build 12.3.2.4934. This build fixes all three vulnerabilities in the supplied Veeam security advisory.

  • Check the installed build in the Veeam Backup & Replication Console under Main Menu > Help > About, as described in the release and patch notice.

  • For builds 12.3.2.3617, 12.3.2.4165, 12.3.2.4465 or 12.3.2.4854, use the patch ISO or EXE. Earlier version 12 deployments, including 12.3.0 and 12.3.1, must use the full upgrade ISO. Follow the Veeam deployment requirements.

  • If Enterprise Manager is deployed, update it before Veeam Backup & Replication. Review the upgrade checklist and allow for a possible reboot, as directed by the Veeam patch notice.

  • Veeam does not list a workaround for these three CVEs in KB4934. Do not treat access restrictions as a replacement for patching.


Summary for IT Teams

  • Products: Veeam Backup & Replication version 12 and Veeam Backup Enterprise Manager.

  • Threat Level: Critical overall, CVSS v4.0 9.4. The other two flaws are Medium, with scores of 6.1 and 4.8.

  • Action Required: Update affected deployments to build 12.3.2.4934 using the appropriate patch or full ISO. Update Enterprise Manager first where present. Version 13 is not affected by these three CVEs.

  • Sources: Veeam security advisory and Veeam release and deployment information.


Reference


Need Help?

If your organisation needs assistance assessing or patching Veeam Backup & Replication, the Secure ISS SOC team is ready to help. Call 1300 769 460 or email the Secure ISS SOC team. Find our details on the Secure ISS contact page.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.