T
Threats
Veeam Backup & Replication Remote Code Execution
Overview
Overall Severity: Critical
Advisory Published: 6 October 2026
Vendor Advisory Last Updated: 6 October 2026
Veeam's security advisory KB4934 covers one Critical and two Medium vulnerabilities. Organisations running affected version 12 builds should prioritise the vendor update. Exploitation prerequisites differ: the server-side flaws require the Backup Viewer role, while the Enterprise Manager cross-site scripting flaw requires an authenticated portal user to open a crafted link.
Affected Versions
Veeam Backup & Replication - CVE-2025-64393 and CVE-2026-93026
Affected: Veeam Backup & Replication 12.3.2 P3, build 12.3.2.4854, and all earlier version 12 builds.
Fixed: Veeam Backup & Replication 12.3.2 P4, build 12.3.2.4934.
Not affected: All Veeam Backup & Replication version 13 builds.
Source: Veeam KB4934: Vulnerabilities resolved in Veeam Backup & Replication 12.3.2 P4.
Veeam Backup Enterprise Manager - CVE-2025-64392
Affected: Veeam Backup Enterprise Manager, the Veeam Backup & Replication component, build 12.3.2.4854 and all earlier version 12 builds.
Fixed: Veeam Backup & Replication 12.3.2 P4, build 12.3.2.4934, including the Enterprise Manager component.
Not affected: Version 13 builds.
Source: Veeam KB4934: Enterprise Manager cross-site scripting advisory.
Vulnerability Breakdown
CVE-2025-64393 - Remote Code Execution Through Insecure Deserialisation
Severity: Critical
CVSS: 9.4, CVSS v4.0
Description: Insecure deserialisation of untrusted data received through the Mount Service allows remote code execution on the Veeam Backup Server.
Impact: An attacker can execute code on the backup server, threatening the confidentiality, integrity and availability of the backup environment.
Conditions: The attacker requires a low-privileged account with the Backup Viewer role. The vendor's CVSS vector indicates no user interaction is required.
Source: Veeam KB4934: CVE-2025-64393 details.
CVE-2026-93026 - Sensitive Key and Credential Access
Severity: Medium
CVSS: 6.1, CVSS v4.0
Description: An authenticated Backup Viewer can modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials on the Veeam Backup Server.
Impact: Unauthorised alteration or deletion of sensitive key material and disclosure or modification of stored credentials.
Conditions: An authenticated account with the Backup Viewer role is required.
Source: Veeam KB4934: CVE-2026-93026 details.
CVE-2025-64392 - Reflected Cross-Site Scripting
Severity: Medium
CVSS: 4.8, CVSS v4.0
Description: A reflected cross-site scripting flaw in Veeam Backup Enterprise Manager allows an attacker to execute script in an authenticated portal user's browser.
Impact: Unauthorised script execution in the affected user's browser.
Conditions: An authenticated portal user must open a crafted link.
Source: Veeam KB4934: CVE-2025-64392 details.
Mitigation
Update affected version 12 deployments to 12.3.2 P4, build 12.3.2.4934. This build fixes all three vulnerabilities in the supplied Veeam security advisory.
Check the installed build in the Veeam Backup & Replication Console under Main Menu > Help > About, as described in the release and patch notice.
For builds 12.3.2.3617, 12.3.2.4165, 12.3.2.4465 or 12.3.2.4854, use the patch ISO or EXE. Earlier version 12 deployments, including 12.3.0 and 12.3.1, must use the full upgrade ISO. Follow the Veeam deployment requirements.
If Enterprise Manager is deployed, update it before Veeam Backup & Replication. Review the upgrade checklist and allow for a possible reboot, as directed by the Veeam patch notice.
Veeam does not list a workaround for these three CVEs in KB4934. Do not treat access restrictions as a replacement for patching.
Summary for IT Teams
Products: Veeam Backup & Replication version 12 and Veeam Backup Enterprise Manager.
Threat Level: Critical overall, CVSS v4.0 9.4. The other two flaws are Medium, with scores of 6.1 and 4.8.
Action Required: Update affected deployments to build 12.3.2.4934 using the appropriate patch or full ISO. Update Enterprise Manager first where present. Version 13 is not affected by these three CVEs.
Sources: Veeam security advisory and Veeam release and deployment information.
Reference
Veeam KB4934: Vulnerabilities resolved in Veeam Backup & Replication 12.3.2 P4
Veeam KB2680: Build numbers and versions of Veeam Backup & Replication
Need Help?
If your organisation needs assistance assessing or patching Veeam Backup & Replication, the Secure ISS SOC team is ready to help. Call 1300 769 460 or email the Secure ISS SOC team. Find our details on the Secure ISS contact page.

