logo

Veeam resolves CVSS 9.0 RCE flaw and other security issues

ID: 0152b4a2-15a3-5ed2-ad28-77c5afec46bc

STIX ID: report--0152b4a2-15a3-5ed2-ad28-77c5afec46bc

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Veeam released patches for several Backup & Replication vulnerabilities, notably a critical RCE (CVE-2025-59470, CVSS 9.0) that can be abused by Backup or Tape Operator roles via malicious interval or order parameters, plus other flaws (CVE-2025-55125, CVE-2025-59468, CVE-2025-59469) enabling RCE or file write as root; fixes are included in Veeam Backup & Replication 13.0.1.1071 and the vendor reports no clear evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.