logo

Veeam issues patch to close critical remote code execution flaw

ID: a375a5de-e9d8-597d-97dc-a803e7faa7d8

STIX ID: report--a375a5de-e9d8-597d-97dc-a803e7faa7d8

Feed Name: CyberScoop

Threat Score
65/100

Date Published: 2026-01-07

Date Updated: 2026-04-21

Author: Greg Otto

...
...

Veeam issued an update for Backup & Replication v13 to fix CVE-2025-59470, a remote code execution vulnerability that could allow users assigned the Backup Operator or Tape Operator roles to execute commands as the product's 'postgres' database user; Veeam lists the CVSS score as 9.0 but treats the issue as high severity because it requires those privileged roles and there are no reports of active exploitation. See Veeam KB: https://www.veeam.com/kb4792

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.