logo

Veeam Backup & Replication: Critical RCE Patched

ID: efb903b3-b134-5b06-8f0e-bbc6e92063f5

STIX ID: report--efb903b3-b134-5b06-8f0e-bbc6e92063f5

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2025-06-18

Date Updated: 2026-07-22

...
...

Veeam released security updates addressing three vulnerabilities: CVE-2025-23121 (critical RCE, CVSS 9.9) affecting domain-joined Backup & Replication servers, CVE-2025-24286 (high, allows Backup Operator to modify jobs potentially leading to code execution), and CVE-2025-24287 (medium local privilege escalation in Veeam Agent for Windows); exploitation requires authentication and Veeam recommends patching to VBR 12.3.2 (build 12.3.2.3617) and Agent 6.3.2 (build 6.3.2.1205) and considering management isolation from production AD.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.