# Veeam Backup & Replication multiple flaws patched

Published: 2026-10-07 · Severity: routine
Canonical: https://vorant.io/reports/0515b0b9-0d58-53a4-9064-cbc2bf28e601/veeam-backup-replication-multiple-flaws-patched

> CERT-FR advisory covers multiple Veeam Backup & Replication vulnerabilities allowing RCE, data exposure, and XSS; patch to 12.3.2 P4.

CERT-FR issued an advisory detailing multiple vulnerabilities in Veeam Backup & Replication affecting versions prior to 12.3.2 P4 (build 12.3.2.4934). The vulnerabilities, tracked as CVE-2025-64392, CVE-2025-64393, and CVE-2026-93026, could allow an attacker to achieve remote arbitrary code execution, compromise data confidentiality, and conduct indirect remote code injection via cross-site scripting (XSS).

No evidence of in-the-wild exploitation is mentioned in the advisory. Veeam published the fixes in security bulletin kb4934 on October 6, 2026. Given Veeam's role as a common target for ransomware actors seeking to disable backups prior to encryption, organizations running affected versions should prioritize patching to the fixed build.

Defenders should verify their Veeam Backup & Replication deployments are updated to version 12.3.2 P4 (build 12.3.2.4934) or later and review the vendor bulletin for further technical details and any applicable workarounds.

## Mentioned in this report

- Vulnerabilities: CVE-2025-64392, CVE-2025-64393, CVE-2026-93026

## Detection guidance (public sample)

### Veeam Backup Service Spawning Command Shell or Scripting Host

ATT&CK: T1190

Veeam Backup & Replication service processes spawning shells or script interpreters, a post-exploitation sign of RCE against the Veeam server. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Veeam Backup Service Spawning Command Shell or Scripting Host
description: Detects Veeam Backup & Replication server-side service processes spawning
  cmd, PowerShell, or script hosts. Remote code execution flaws in Veeam B&R (e.g.
  the CVE-2025-64392/64393 advisory) would be expected to show up as the Veeam service
  process launching an interpreter. Behavioural, not tied to any specific payload.
tags:
- attack.initial-access
- attack.execution
- attack.t1190
- attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith:
    - \Veeam.Backup.Service.exe
    - \Veeam.Backup.CatalogDataService.exe
    - \VeeamDeploymentSvc.exe
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wscript.exe
    - \cscript.exe
    - \mshta.exe
    - \rundll32.exe
    - \certutil.exe
    - \bitsadmin.exe
  condition: selection
falsepositives:
- Administrator-configured pre/post-job scripts launched through Veeam services
- Veeam deployment or upgrade routines invoking PowerShell or cmd
level: medium
id: f83b468f-2b81-5500-84f7-02946020644a
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1278
```

### Veeam Services Stopped or Killed via Command Line

ATT&CK: T1489

net/sc/taskkill/Stop-Service targeting Veeam services, typical of ransomware operators disabling backups before encryption. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Veeam Services Stopped or Killed via Command Line
description: Detects command-line attempts to stop or kill Veeam services or processes
  using net, sc, taskkill or Stop-Service. Ransomware actors commonly disable Veeam
  Backup & Replication before encryption, and exploitation of Veeam flaws is a likely
  precursor.
tags:
- attack.impact
- attack.t1489
logsource:
  category: process_creation
  product: windows
detection:
  selection_net:
    Image|endswith:
    - \net.exe
    - \net1.exe
    - \sc.exe
    CommandLine|contains|all:
    - stop
    - veeam
  selection_taskkill:
    Image|endswith: \taskkill.exe
    CommandLine|contains: veeam
  selection_ps:
    CommandLine|contains|all:
    - Stop-Service
    - veeam
  filter_installer:
    ParentImage|endswith: \msiexec.exe
  condition: 1 of selection_* and not filter_installer
falsepositives:
- Administrators stopping Veeam services manually for maintenance or patching
- Patch or upgrade scripts that stop Veeam services before updating
level: medium
id: 0e2588e5-0d52-5e86-9575-063f4173cc01
status: experimental
author: Vorant
references:
- https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1278
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1278

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0515b0b9-0d58-53a4-9064-cbc2bf28e601/veeam-backup-replication-multiple-flaws-patched.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
