Veeam's two official documents don't count the CVEs the same way. The dedicated security advisory, KB4934, lists three vulnerabilities. The 12.3 release-information page, KB4696, lists four for the same build. The extra one is a Cloud Connect file-read bug. The details are below.
What Veeam Fixed in Build 12.3.2.4934
The KB4934 advisory says the issues it covers affect only Veeam Backup & Replication 12.3.2 P3 (build 12.3.2.4854) and older builds and are fixed in build 12.3.2.4934. Veeam also says no version 13 builds are affected by these three issues. Veeam reminds customers that version 12 reaches end of support on February 28, 2027.
KB4696, the release notes for 12.3 and its updates, lists four CVEs under build 12.3.2.4934. All four scores are CVSS 4.0.
| CVE | Severity (CVSS 4.0) | What it allows | Who can trigger it |
|---|---|---|---|
| CVE-2025-64393 | Critical (9.4) | Remote code execution on the Backup Server through Mount Service deserialization | Low-privileged user with the Backup Viewer role |
| CVE-2026-58069 | High (8.3) | Reading arbitrary files on the service provider host | Authenticated Veeam Cloud Connect tenant |
| CVE-2026-93026 | Medium (6.1) | Changing or deleting the Enterprise Manager master key; reading or overwriting stored antivirus-update credentials | Authenticated Backup Viewer |
| CVE-2025-64392 | Medium (4.8) | Reflected XSS: script runs in the browser of an Enterprise Manager user | Authenticated portal user who opens a crafted link |
Summary: One build, four CVEs in the release notes, three in the security advisory. Two of the three advisory bugs only need the lowly Backup Viewer role.
The Headline Bug: CVE-2025-64393
Veeam's release notes describe CVE-2025-64393 as a vulnerability allowing a low-privileged user with the Backup Viewer role to perform remote code execution (RCE) on the Veeam Backup Server through insecure deserialization of untrusted data received via the Mount Service.
The CVSS 4.0 vector Veeam published is AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. In plain terms:
- Network-reachable (AV:N)
- Low complexity, with no special attack conditions (AC:L, AT:N)
- Needs a low-privilege account (PR:L). This is not an unauthenticated bug.
- No user interaction (UI:N)
- High impact on the backup server and on systems beyond it (the "S" metrics)
Backup Viewer is meant to be a read-only role. In many organisations it gets handed to help desk staff, auditors and monitoring service accounts. A role that's supposed to just look at backup sessions can, on unpatched builds, run code on the server.
Veeam's Mount Service has caused trouble before. KB4696 shows that the October 2025 build fixed CVE-2025-48983, a 9.9-rated (CVSS 3.1) Mount service RCE. That one could be exploited by an authenticated domain user and only hit domain-joined backup infrastructure servers.
The Other Three
CVE-2026-93026 (Medium, 6.1). A Backup Viewer can change or delete the Enterprise Manager master key and read or overwrite stored antivirus-update credentials. Its vector includes AT😛, meaning some attack precondition has to exist. The integrity impact is still rated high.
CVE-2025-64392 (Medium, 4.8). This is the "malicious script" bug in many headlines. Per KB4696, it allows an attacker to execute script in the browser of an authenticated portal user who opens a crafted link. Someone has to click, and the victim's portal session sets the limit on what the attacker can do. Some coverage frames the victim as an administrator, but Veeam's wording says "authenticated portal user."
CVE-2026-58069 (High, 8.3). KB4696 lists this as letting an authenticated Veeam Cloud Connect tenant to read arbitrary files on the service provider host. It is not in KB4934. Cybersecurity News reports that unlike the three vulnerabilities described in KB4934, this issue also affects specified version 13 builds and has separate fixes for those releases. The Veeam material we inspected doesn't name those version 13 builds, so treat the v13 detail as secondary reporting for now. In practice, Cloud Connect service providers on version 13 should check Veeam's v13 advisories rather than assume they're clear because KB4934 says "version 13 not affected."
Most of the fixes concern the backup server, but the bug the headlines lead with lives in Enterprise Manager. Cloud Connect providers, meanwhile, have their own separate exposure.
Is Anyone Exploiting This?
Veeam hasn't said these flaws are being exploited, and nobody else has reported it either. GBHackers put it well: the disclosure also does not confirm whether exploitation has occurred in the wild. However, these omissions should not be interpreted as a reassurance that affected installations are safe.
KB4934 itself warns that once a patch is public, attackers will probably reverse-engineer it to go after unpatched systems. Veeam has been here before. SecurityWeek has noted that CISA's Known Exploited Vulnerabilities (KEV) catalog includes four weaknesses found in the product in recent years, including CVE-2024-40711 and CVE-2023-27532, both exploited in ransomware attacks.
A Busy Year of Veeam Patches
This is the third security release for the 12.3.2 line in 2026, according to KB4696:
- 12.3.2.4465 (March 12, 2026): Fixed CVE-2026-21666, CVE-2026-21667 and CVE-2026-21708, each Critical 9.9. The first two were domain-user RCEs; CVE-2026-21708 let a Backup Viewer run code as the postgres user. Those scores are CVSS 3.1, so don't compare them directly with this month's CVSS 4.0 numbers.
- 12.3.2.4854 (June 2026): Fixed CVE-2026-44963, a Critical 9.4 (CVSS 4.0) RCE that an authenticated domain user could trigger.
- 12.3.2.4934 (October 6, 2026): This release.
KB4696 also covers 2025 releases that fixed domain-user RCEs CVE-2025-23120, CVE-2025-23121, CVE-2025-48983 and CVE-2025-48984. Veeam noted that several of those only affected domain-joined servers, which is why it keeps pointing admins to its workgroup-versus-domain guidance.
Non-Security Fixes in the Same Build
KB4696 lists two other fixes in 12.3.2.4934:
- Managed servers: Re-adding a Linux server after it was removed from the backup infrastructure no longer fails with "SSH credentials for host '<guid>' not found."
- Veeam Agent for Microsoft Windows: Installing or upgrading the agent on Windows 7 and Windows Server 2008 R2 no longer fails with an unsupported-OS / missing service pack error.
The second fix will please anyone still nursing old Windows boxes in a corner of the data centre.
How to Patch: Step by Step
Here's the procedure, based on Veeam's KB4696 release information:
- Check your build. Open the Veeam Backup & Replication Console and go to Main Menu (≡) > Help > About. If it says 12.3.2.4854 or anything older in version 12, you're affected.
- Choose the right package.
- The patch ISO/EXE only works on builds 12.3.2.3617, 12.3.2.4165, 12.3.2.4465 and 12.3.2.4854. Both formats contain the same patch. The EXE is smaller but has to extract itself first.
- The full 12.3.2 ISO is for new installs and for upgrading from 11a, 12, 12.1, 12.2, 12.3.0 or 12.3.1.
- If you run the patch on an unsupported build, the installer says "This update is not compatible with installed product version."
- Unblock the downloaded ISO. Veeam gives this PowerShell command:
Unblock-File -Path "C:\Path\to\File\VeeamBackup&Replication_12.3.2.4934_20260918_patch.iso". If you skip it, installation can fail with a "Could not load file or assembly … ServiceOperation.dll" error. Veeam publishes this SHA256 for the patch ISO:A4EA29B4E71F06DC7A55529AE30F4608672ACD3C6D01DE1E4EBC4C8F463490DA. - Patch Enterprise Manager first. If you use Enterprise Manager, update it before Backup & Replication.
- Plan for a reboot. Veeam says one may be needed.
- Embedded deployments count too. Veeam Recovery Orchestrator 7.2.1 runs an embedded copy of Backup & Replication 12.3.2. Veeam recommends updating it with the same patch.
- Confirm. Go back to Help > About and make sure the build reads 12.3.2.4934.
Hardening While You Wait
These steps reduce risk until you can patch. They don't replace the patch.
- Audit Backup Viewer assignments. Two of the three KB4934 bugs start from this role. Remove it from accounts that don't need it.
- Limit Enterprise Manager exposure. Restrict portal access to trusted networks and tell users not to open unsolicited links to the portal.
- Look at domain membership. Veeam's security best-practice guide covers whether to run backup infrastructure in a workgroup or a domain, and earlier domain-user RCEs show why it matters.
- If you suspect tampering, treat the Enterprise Manager master key and stored antivirus-update credentials as compromised. Follow Veeam's procedures to rotate them, and check logs for unexpected logins by low-privilege accounts.
- Plan for version 13. Version 12 support ends February 28, 2027, less than five months away. Veeam says the three KB4934 bugs don't affect version 13. If you run Cloud Connect, check the reported v13 exposure for CVE-2026-58069 before you count on that.
The Bottom Line
If you run Veeam Backup & Replication 12, install 12.3.2.4934. Next, review who holds the Backup Viewer role. Then start your version 13 migration plan before the February deadline.
References
- Veeam Backup & Replication Vulnerability Allow Attackers to Execute Malicious Script Cyber Press · 2026-10-07T09:51:08+00:00
- Critical Veeam Backup & Replication Flaw Allows Low-Privileged Users to Execute Remote Code gbhackers.com
- Several Code Execution Flaws Patched in Veeam Backup & Replication ... securityweek.com