Back

Veeam Releases Security Update to Address Multiple Vulnerabilities

At a glance

  • Veeam issued Backup & Replication build 12.3.2 P4 on October 6, 2026.
  • The update resolved a critical remote code execution vulnerability.
  • Several other security flaws, including XSS and privilege issues, were fixed.

Veeam released a security update for its Backup & Replication software on October 6, 2026, addressing several vulnerabilities in previous versions. The update, identified as build 12.3.2 P4 (12.3.2.4934), was made available to users through the company’s official channels.

The new build fixed a critical remote code execution vulnerability tracked as CVE-2025-64393, which affected versions 12.3.2 P3 and earlier of Veeam Backup & Replication. This vulnerability could have allowed unauthorized code to run on affected systems if left unpatched.

In addition to the critical issue, the update addressed a reflected cross-site scripting (XSS) vulnerability in Enterprise Manager, referenced as CVE-2025-64392. This flaw permitted script execution in the browser of an authenticated user, increasing the risk of unauthorized actions within the application.

The release also corrected a medium-severity vulnerability, CVE-2026-93026, which enabled an authenticated Backup Viewer to alter or remove the Enterprise Manager master key and access antivirus update credentials. This issue could have impacted the integrity of backup management and credential security.

What the numbers show

  • Build 12.3.2 P4 (12.3.2.4934) was released on October 6, 2026.
  • CVE-2025-64393 affected all versions up to 12.3.2 P3.
  • At least four distinct vulnerabilities were resolved in this update.

Another vulnerability, CVE-2026-58069, was also resolved as part of the same update. Details of this issue were included in Veeam’s published security documentation for build 12.3.2.4934.

Veeam’s security advisories provided information on the vulnerabilities and the steps taken to address them in the latest release. Users of affected versions were advised to apply the update to mitigate the identified risks.

The company’s knowledge base and security fix documentation outlined the technical details of each vulnerability and the specific components impacted. The update was distributed through official support channels to ensure accessibility for customers managing backup environments.

By releasing build 12.3.2 P4, Veeam addressed multiple security concerns in its Backup & Replication platform, aiming to enhance the overall protection of user data and system integrity.

* This article is based on publicly available information at the time of writing.