Veeam Patches Critical Code Execution Flaw in Backup & Replication

Veeam has issued a fix for CVE-2025-64393, a critical remote code execution flaw in Backup & Replication. The vulnerability has a CVSS 4.0 score of 9.4 and can be exploited by an authenticated user with the Backup Viewer role. It stems from insecure deserialization and could let such a user run arbitrary code on the Veeam Backup Server.
Veeam's update targets a severe flaw, CVE-2025-64393, in Backup & Replication. Rated 9.4 under CVSS 4.0, it allows a user already holding the Backup Viewer role to trigger remote code execution on the backup server. The root cause is unsafe handling of deserialized data through the Mount Service.
The fix arrived on October 6, 2026, as Backup & Replication 12.3.2 P4, build 12.3.2.4934. All 12.x releases through 12.3.2.4854 are affected, while version 13 is not vulnerable. Because backup systems hold sensitive recovery assets, exploitation could give attackers deeper access.
Organizations that depend on Veeam backup infrastructure could face heightened risk if the flaw is exploited before patching. An attacker with the Backup Viewer role might reach recovery systems, credentials, or other sensitive resources, potentially disrupting restoration capabilities. This may affect IT and security teams, their customers, and broader service continuity. The practical impact could include costly incident response, data recovery delays, and reduced confidence in backup platforms, though timely updates and monitoring may limit exposure.