Veeam announced on Tuesday that an update released for its Backup & Replication solution patches several vulnerabilities that can be exploited for remote code execution.
The security holes impact Veeam Backup & Replication 13.0.1.180 and earlier, and they have been fixed with the release of version 13.0.1.1071
One of the vulnerabilities is CVE-2025-59470, which can be exploited by an attacker with ‘backup’ or ‘tape operator’ privileges for remote code execution as the ‘postgres’ user by leveraging specially crafted parameters.
The flaw has a critical severity based on its CVSS score, but Veeam adjusted the severity to high because the roles required for exploitation are considered highly privileged.
A high severity rating has also been assigned to CVE-2025-55125, which allows an attacker with ‘tape operator’ or ‘backup’ privileges to execute arbitrary code as root using malicious backup configuration files.
CVE-2025-59469, another high-severity issue, requires the same types of privileges and enables an attacker to write files to the system as root.
The last vulnerability, CVE-2025-59468, allows an attacker with ‘backup administrator’ privileges to perform remote code execution.
All of these vulnerabilities were discovered internally by Veeam and there is no indication that they have been exploited in the wild.
However, it’s important for organizations to address the flaws, as it’s not uncommon for threat actors to target Veeam Backup & Replication in their attacks.
CISA’s Known Exploited Vulnerabilities (KEV) catalog includes four weaknesses found in the product in recent years, including CVE-2024-40711 and CVE-2023-27532, both exploited in ransomware attacks.
Related: Veeam Patches Critical Vulnerability in Backup & Replication
Related: Code Execution Vulnerabilities Patched in Veeam, BeyondTrust Products
Related: Veeam Warns of Critical Vulnerability in Service Provider Console
