VORANT. Threat Intelligence Research Sign in Create a free account

Veeam Backup & Replication multiple flaws patched

routine vulnerability

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory covers multiple Veeam Backup & Replication vulnerabilities allowing RCE, data exposure, and XSS; patch to 12.3.2 P4.

CERT-FR issued an advisory detailing multiple vulnerabilities in Veeam Backup & Replication affecting versions prior to 12.3.2 P4 (build 12.3.2.4934). The vulnerabilities, tracked as CVE-2025-64392, CVE-2025-64393, and CVE-2026-93026, could allow an attacker to achieve remote arbitrary code execution, compromise data confidentiality, and conduct indirect remote code injection via cross-site scripting (XSS).

No evidence of in-the-wild exploitation is mentioned in the advisory. Veeam published the fixes in security bulletin kb4934 on October 6, 2026. Given Veeam's role as a common target for ransomware actors seeking to disable backups prior to encryption, organizations running affected versions should prioritize patching to the fixed build.

Defenders should verify their Veeam Backup & Replication deployments are updated to version 12.3.2 P4 (build 12.3.2.4934) or later and review the vendor bulletin for further technical details and any applicable workarounds.

Mentioned in this report

Vulnerabilities CVE-2025-64392CVE-2025-64393CVE-2026-93026

Detection guidance

Veeam Backup Service Spawning Command Shell or Scripting Host

ATT&CK T1190

Veeam Backup & Replication service processes spawning shells or script interpreters, a post-exploitation sign of RCE against the Veeam server. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Veeam Backup Service Spawning Command Shell or Scripting Host
description: Detects Veeam Backup & Replication server-side service processes spawning
  cmd, PowerShell, or script hosts. Remote code execution flaws in Veeam B&R (e.g.
  the CVE-2025-64392/64393 advisory) would be expected to show up as the Veeam service
  process launching an interpreter. Behavioural, not tied to any specific payload.
tags:
- attack.initial-access
- attack.execution
- attack.t1190
- attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith:
    - \Veeam.Backup.Service.exe
    - \Veeam.Backup.CatalogDataService.exe
    - \VeeamDeploymentSvc.exe
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
    - \rundll32.exe
    - \certutil.exe
    - \bitsadmin.exe
  condition: selection
falsepositives:
- Administrator-configured pre/post-job scripts launched through Veeam services
- Veeam deployment or upgrade routines invoking PowerShell or cmd
level: medium
id: f83b468f-2b81-5500-84f7-02946020644a
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1278

Veeam Services Stopped or Killed via Command Line

ATT&CK T1489

net/sc/taskkill/Stop-Service targeting Veeam services, typical of ransomware operators disabling backups before encryption. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Veeam Services Stopped or Killed via Command Line
description: Detects command-line attempts to stop or kill Veeam services or processes
  using net, sc, taskkill or Stop-Service. Ransomware actors commonly disable Veeam
  Backup & Replication before encryption, and exploitation of Veeam flaws is a likely
  precursor.
tags:
- attack.impact
- attack.t1489
logsource:
  category: process_creation
  product: windows
detection:
  selection_net:
    Image|endswith:
    - \net.exe
    - \net1.exe
    - \sc.exe
    CommandLine|contains|all:
    - stop
    - veeam
  selection_taskkill:
    Image|endswith: \taskkill.exe
    CommandLine|contains: veeam
  selection_ps:
    CommandLine|contains|all:
    - Stop-Service
    - veeam
  filter_installer:
    ParentImage|endswith: \msiexec.exe
  condition: 1 of selection_* and not filter_installer
falsepositives:
- Administrators stopping Veeam services manually for maintenance or patching
- Patch or upgrade scripts that stop Veeam services before updating
level: medium
id: 0e2588e5-0d52-5e86-9575-063f4173cc01
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1278

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1278

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,945 reports from 148 sources, 471 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs