Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Veeam Backup RCE Flaws Allow Remote Execution of Malicious Code

Veeam has issued a critical security update addressing multiple remote code execution (RCE) vulnerabilities in Veeam Backup & Replication version 12. These vulnerabilities could enable authenticated domain users to execute malicious code on backup…

Veeam has issued a critical security update addressing multiple remote code execution (RCE) vulnerabilities in Veeam Backup & Replication version 12. These vulnerabilities could enable authenticated domain users to execute malicious code on backup servers and infrastructure hosts. Immediate application of this patch is necessary to mitigate potential breaches.

The most severe vulnerabilities impact domain-joined Veeam Backup & Replication v12 installations:

CVE-2025-48983: This vulnerability targets the Mount service on backup infrastructure hosts, allowing an authenticated domain user to execute arbitrary code remotely. It has a CVSS v3.1 score of 9.9. CVE-2025-48984: An authenticated domain user can achieve RCE on the primary backup server. This vulnerability also has a CVSS v3.1 score of 9.9.

Additionally, a high-severity local privilege escalation vulnerability, CVE-2025-48982 , exists in Veeam Agent for Microsoft Windows. This can be exploited if an administrator restores a malicious file, leading to elevated system privileges. It has a CVSS v3.1 score of 7.3.

All identified vulnerabilities have been rectified in the Veeam Backup & Replication 12.3.2.4165 patch and the Veeam Agent for Microsoft Windows 6.3.2.1302 update. Veeam’s Vulnerability Disclosure Program ensures timely patch development and provides mitigation instructions. Organizations are advised to immediately apply the latest updates and verify that all systems are running the updated software versions.

Veeam has issued a critical security update addressing multiple remote code execution (RCE) vulnerabilities in Veeam Backup & Replication version 12.
Noah Kensington · Thehackingpost

Administrators should consult the Veeam Backup & Replication Security Best Practice Guide to minimize attack surfaces and ensure robust security configurations. Regular audits and strict access controls are recommended to further mitigate exploitation risks.

CVE ID Description Severity CVSS Score

CVE-2025-48983 RCE via Mount service on backup infrastructure hosts by authenticated user Critical 9.9

CVE-2025-48984 RCE on backup server by authenticated domain user Critical 9.9

Advertisement

CVE-2025-48982 Local privilege escalation in Veeam Agent for Microsoft Windows when restoring malicious file High 7.3

Organizations utilizing Veeam Backup & Replication version 12 or Veeam Agent for Windows should ensure the patches released on October 14, 2025, are applied. Prompt updates are crucial to defend against known exploits and unauthorized code execution in backup environments.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories