logo

Veeam patches third critical RCE bug in Backup & Replication in space of a year

ID: c2f34ec0-e0bb-5f46-a861-ae5bc0f1ab17

STIX ID: report--c2f34ec0-e0bb-5f46-a861-ae5bc0f1ab17

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2025-06-18

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Veeam Backup & Replication suffers critical RCE vulnerabilities (CVE-2025-23121, CVE-2025-23120, and CVE-2024-40711) due to uncontrolled deserialization via BinaryFormatter on domain-joined servers; patches addressing CVE-2025-23121 are available for affected v12 builds (12.3.1.1139), and Veeam plans to remove BinaryFormatter in v13. Multiple ransomware groups have previously exploited related flaws in the wild, increasing the urgency to patch and avoid domain-joining backup servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.