« All news

AlertCritical

Veeam patches a critical Backup & Replication flaw that allows code execution as SYSTEM

A critical vulnerability (CVE-2025-64393, CVSS 9.4) lets a user with the read-only Backup Viewer role run arbitrary code with SYSTEM privileges on the backup server. Veeam has fixed it in Backup & Replication 12.3.2 P4.

What happened

On 6 October 2026 Veeam published advisory KB4934, which resolves a critical vulnerability in Veeam Backup & Replication tracked as CVE-2025-64393. The flaw carries a CVSS score of 9.4 out of 10 (critical).

According to the published description, the issue allows a user holding the Backup Viewer role — a low-privileged, read-oriented profile — to execute arbitrary code with SYSTEM permissions on the backup server. In practice, a simple viewing account can end up taking full control of the backup infrastructure, which is exactly the last line of defence during a ransomware incident.

Who is affected

Veeam's advisory sets out the scope clearly:

Exploitation status

There is no confirmed active exploitation at this time: the vulnerability is not listed in CISA's KEV catalogue and no public exploit code is known. FIRST has not yet assigned an EPSS score, so there is no published estimate of exploitation likelihood.

That should not be read as a reason to delay. Veeam itself notes in the advisory that once a vulnerability and its patch are disclosed, attackers commonly reverse-engineer the fix to target deployments that have not been updated. Backup servers are also a priority target in ransomware operations.

What to do

We recommend acting within days rather than waiting for the usual maintenance window, particularly if the server is network-exposed or if external users hold roles in the console.

Context

The vendor advisory does not describe any temporary or alternative mitigation: the stated remedy is installing the P4 patch. Veeam also reports no known incidents linked to this flaw.

If your organisation relies on Veeam as the backbone of its recovery strategy, this server deserves the same criticality rating as a domain controller, both in patching cadence and in access control.

Sources

Affected technologies

Veeam Backup & Replication

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2025-64393Critical (9.4)—10/7/2026Received

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.