Veeam Backup & Replication 12.3.2 P4 (KB4934, 6 Oct): a Backup Viewer account can get remote code execution on the backup server through Mount Service deserialization (CVE-2025-64393, CVSS 4.0 9.4); also fixes Enterprise Manager XSS, master-key tampering and a Cloud Connect tenant file read
Veeam released Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934) on 6 October 2026 and listed the security fixes in KB4934. The serious one is CVE-2025-64393, rated Critical at CVSS 4.0 9.4: a low-privileged user holding only the Backup Viewer role can run code on the Veeam Backup Server through insecure deserialization of data received by the Mount Service, with no user interaction. CVE-2026-93026 (6.1) lets a Backup Viewer user change or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials, and CVE-2025-64392 (4.8) is a reflected cross-site scripting flaw in Veeam Backup Enterprise Manager that needs a logged-in portal user to open a crafted link. These three affect build 12.3.2.4854 and earlier version 12 builds; Veeam says version 13 is not affected by them. The same patch also carries the fix for CVE-2026-58069 (8.3), first published in KB4902 for version 13.1, which lets an authenticated Veeam Cloud Connect tenant read any file on the service provider's host; for version 13 that one is fixed in 13.0.3.63 and 13.1.0.411. All four were reported through HackerOne, and no exploitation has been reported. Backup servers are a favourite ransomware target, and Veeam flaws have been weaponised quickly after past patches. Version 12 reaches end of support on 28 February 2027. Primary: Veeam KB4934.
- Product
- Veeam Backup & Replication (backup server, Mount Service, Enterprise Manager, Cloud Connect)
- Versions
- 12.3.2.4854 and earlier version 12 builds (fixed 12.3.2.4934). CVE-2026-58069 also hits 13.0.2.29 and earlier 13 builds (fixed 13.0.3.63 / 13.1.0.411). Unsupported versions presumed affected.
- CVSS
- Critical (CVE-2025-64393, CVSS 4.0, Veeam); 8.3 (CVE-2026-58069); 6.1 (CVE-2026-93026); 4.8 (CVE-2025-64392)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade version 12 backup servers to 12.3.2 P4 (build 12.3.2.4934); check the build under Help > About in the console. Version 13 servers: move to 13.0.3.63 or 13.1.0.411 for the Cloud Connect fix. Review who holds the Backup Viewer role and remove it where not needed, keep backup servers off the domain and off user networks, and plan the move off version 12 before end of support in February 2027.
Primary: Veeam — KB4934: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 (published 6 Oct 2026) · Vendor: Veeam — KB4902: Vulnerabilities Resolved in Veeam Backup & Replication 13.1 (CVE-2026-58069) · CVE: CVE-2025-64393, CVE-2026-93026, CVE-2025-64392, CVE-2026-58069 · Cyber Security News — Veeam Backup and Replication vulnerability (7 Oct 2026)
