<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1741336722824154&amp;ev=PageView&amp;noscript=1">
Skip to the main content.
Print Solutions

Benefit from smart ideas, lower costs, greater productivity. Choose from award-winning printers, software solutions and consumables

Insights

We combine professional expertise with a human kind of partnership

Support Centre

Get the right help and advice, register a product and see why our commitment to you matters.

Kyocera_lead_Huon_IT_co branding_RGB

Critical Security Advisory – Veeam Backup & Replication Vulnerabilities

Critical Security Advisory – Veeam Backup & Replication Vulnerabilities

We'd like to make you aware of several security vulnerabilities recently disclosed by Veeam affecting Veeam Backup & Replication v12. The most serious carries a CVSS score of 9.4 and could allow remote code execution on the backup server, so we recommend prompt attention.

Summary of the Vulnerabilities:
  • CVE-2025-64393 (CVSS 9.4, Critical) – A remote code execution (RCE) flaw. A low-privileged user holding the Backup Viewer role could execute code on the Veeam Backup Server via insecure deserialization of untrusted data through the Mount Service.
  • CVE-2026-93026 (CVSS 6.1, Medium) – An authenticated user with the Backup Viewer role could modify or delete the Enterprise Manager master key, and read or overwrite stored antivirus update credentials on the backup server.
  • CVE-2025-64392 (CVSS 4.8, Medium) – A reflected cross-site scripting (XSS) flaw in Veeam Backup Enterprise Manager, allowing an attacker to run script in the browser of an authenticated portal user who opens a crafted link.
  • Important: Version 13 builds are not affected. All three issues affect v12 builds up to and including 12.3.2 P3 (build 12.3.2.4854).
  • Full Veeam article can be found here.

 

What's Affected:

  • Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 (builds 12.3.2.4854 and earlier)
  • Veeam Backup & Replication v13 is not affected.
  • Please note: Veeam Backup & Replication v12 reaches End of Support on 28 February 2027, worth factoring into any upgrade planning.
Recommended Action:

We strongly encourage reviewing your environment to identify if you are running an affected version. All three vulnerabilities are resolved in Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934), and we recommend updating to this build (or later) as soon as possible to reduce exposure. Once a vulnerability and its patch are publicly disclosed, attackers commonly attempt to reverse-engineer the fix to target unpatched deployments, so prompt patching matters here.

At Kyocera, we understand the critical importance of securing your infrastructure. If you need help reviewing your environment, checking for compromise or applying the update, please contact our team. You can reach our helpdesk at help@dau.kyocera.com.