Critical Vulnerability in Veeam Backup & Replication
9 October 2026
Attackers with the Backup Viewer role can exploit a critical vulnerability in Veeam Backup & Replication to execute arbitrary code as SYSTEM. Patch immediately.
Critical Vulnerability in Veeam Backup & Replication
Attackers with the Backup Viewer role can exploit a critical vulnerability in Veeam Backup & Replication to execute arbitrary code as SYSTEM. Patch immediately.
Background
Veeam has released security updates addressing a critical vulnerability (CVE-2025-64393) affecting Veeam Backup & Replication. This vulnerability has a Common Vulnerability Scoring System (CVSS v4.0) score of 9.4 out of 10.
Impact
Successful exploitation of this vulnerability could allow an attacker with the Backup Viewer role to perform remote code execution on the Veeam Backup Server through insecure deserialisation of untrusted data received via the Mount Service.
Affected Products
The vulnerability affects Veeam Backup & Replication versions 12 through 12.3.2.4854.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://www.veeam.com/KB4934 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2025-64393 (opens in new tab)
