
Veeam released Backup & Replication 12.3.2 P4 on October 6, and the headliner is ugly: CVE-2025-64393, a CVSS 4.0 score of 9.4, lets a user with the low-privileged Backup Viewer role run arbitrary code on the backup server. No admin account needed. No user interaction. The flaw is insecure deserialization of data passed through the Mount Service, reported through HackerOne, and it was fixed in build 12.3.2.4934.
Two more flaws in the same release target the same low-privileged role. CVE-2026-93026 (6.1) lets a Backup Viewer modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials. CVE-2025-64392 (4.8) is a reflected cross-site scripting bug in Enterprise Manager that fires when an authenticated portal user opens a crafted link. All three hit version 12 builds up to 12.3.2.4854. Version 13 is not affected, and Veeam is reminding everyone that version 12 reaches end of support on February 28, 2027.
Patch the server. Obviously. But there is a durable point underneath the patch, and it is the reason this post is a tutorial instead of another patch bulletin.
The durable idea: the backup server is the last box standing after ransomware. Everything about its design, its roles, and its network position should assume someone is already inside it. A read-only role that can take the whole server is not a permission problem; it is an architecture assumption that quietly broke. So use this patch as the excuse to do the audit you were always going to do later.
What the three CVEs actually say about your environment
| CVE | Score | Who can use it | What it does |
|---|---|---|---|
| CVE-2025-64393 | 9.4 | Backup Viewer role | RCE on the backup server through the Mount Service |
| CVE-2026-93026 | 6.1 | Backup Viewer role | Modify or delete the Enterprise Manager master key; read or overwrite AV update credentials |
| CVE-2025-64392 | 4.8 | Any authenticated portal user | Reflected XSS in Enterprise Manager from a crafted link |
Note the pattern: the two most severe issues both hinge on a role that sounds harmless. "Backup Viewer" reads like read-only visibility for auditors and managers. The lesson is not that Veeam shipped a bad role; it is that every vendor's "viewer" role deserves the same question: what can this identity actually touch?
Inventory first: find every 12.x backup server you own
Before you patch anything, know what you have. This is the same discipline as the slmgr inventory post last month: you cannot protect what you have not listed.
- Check the build on every Veeam Backup & Replication console: Main Menu, then Help, then About. Anything at 12.3.2.4854 or earlier is affected.
- Include the backup servers you forgot about: lab servers, the old one kept for quarterly restores, the one a departed engineer set up for a single client.
- Record which are on version 12 and which are already on 13. Version 13 is not affected by any of these flaws, and version 12 goes end of support on February 28, 2027, so this inventory doubles as your migration plan.
Patch to 12.3.2 P4 (build 12.3.2.4934)
- Read Veeam's KB4934 first. It lists all three flaws, affected builds, and the fix build.
- Snapshot or back up the backup server itself before upgrading. Yes, really: the thing that holds your backups also needs a rollback path.
- Apply the update during a maintenance window, since the Mount Service is involved in restores.
- Re-verify the build in Help, then About after the update. Close the loop on paper, not just in your head.
Audit the Backup Viewer role
This is the part most shops will skip, and it is the part that matters most. The patch closes the known flaws. The role audit closes the class of problem.
- In Enterprise Manager, list every account holding the Backup Viewer role. Do not assume the list is short.
- For each account, ask: does this person still need portal visibility into backups, or did they get the role for a one-time audit, a demo, or a project that ended two years ago?
- Remove the role from anyone who does not need it this month. "They might need it later" is not a reason; you can re-add it in a minute.
- For the accounts that stay, confirm they are individually named and MFA-protected. No shared "viewer" accounts.
- Set a recurring review. Quarterly is fine for most shops. Put it in the change calendar so it is not a calendar invite you have to remember.
Harden the network position of the backup server
The CVE scores assume network reachability, and the CVSS vector for the RCE is AV:N, low attack complexity, no user interaction. That is the vector telling you the isolation story matters as much as the patch.
- Confirm the backup server cannot be reached from the general user network. If a regular workstation can talk to the Mount Service port, that is a finding, not a convenience.
- Confirm backup repositories are not mounted on the same network segment as user traffic where avoidable.
- If you run Veeam agents on servers that sit in multiple VLANs, document which paths the backup server accepts traffic from and prune the rest.
One date to put on the calendar
Veeam says version 12 reaches end of support on February 28, 2027. P4 is not the end of the road; it is the last reliable bus. Start the version 13 migration planning now, while it is a project and not an emergency.
Conclusion
The patch fixes the deserialization flaw. The audit fixes the assumption that a viewer role is harmless. Do both, and the next low-privilege escalation against your backup infrastructure finds a smaller target: fewer roles, an isolated server, and an inventory that actually exists.
Sources
- Veeam, "KB4934: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4" — https://www.veeam.com/kb4934 (advisory; documents CVE-2025-64393, CVE-2026-93026, CVE-2025-64392, affected builds 12.3.2.4854 and earlier, fixed build 12.3.2.4934, version 13 unaffected, and the February 28, 2027 end-of-support date for version 12)
- GBHackers, "Critical Veeam Backup & Replication Flaw Allows Low-Privileged Users to Execute Remote Code" — https://gbhackers.com/critical-veeam-backup-replication-flaw/ (October 7, 2026; release date October 6, 2026 and affected-build scope)
- Cyber Security News, "Veeam Backup and Replication Vulnerability" — https://cybersecuritynews.com/veeam-backup-and-replication-vulnerability/ (October 7, 2026; fix build and advisory references)
- Cyber Security Agency of Singapore, "Critical Vulnerability in Veeam Backup & Replication" — https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-138/ (October 9, 2026; independent confirmation of the 9.4 RCE via the Backup Viewer role)



