Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication

The Hacker News by The Hacker News
January 7, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Jan 07, 2026Ravie LakshmananVulnerability / Enterprise Security

Veeam has released security updates to address multiple flaws in its Backup & Replication software, including a “critical” issue that could result in remote code execution (RCE).

The vulnerability, tracked as CVE-2025-59470, carries a CVSS score of 9.0.

“This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter,” it said in a Tuesday bulletin.

According to Veeam’s documentation, a user with a Backup Operator role can start and stop existing jobs; export backups; copy backups; and create VeeamZip backups. A Tape Operator user, on the other hand, can run tape backup jobs or tape catalog jobs; eject tapes; import and export tapes; move tapes to a media pool; copy or erase tapes; and set a tape password.

In other words, these roles are considered highly privileged, and organizations should already be taking adequate protections to prevent them from being misused.

Cybersecurity

Veeam said it’s treating the shortcoming as “high severity” despite the CVSS score, stating the opportunity for exploitation is reduced if customers follow Veeam’s recommended Security Guidelines.

Also addressed by the company are three other vulnerabilities in the same product –

  • CVE-2025-55125 (CVSS score: 7.2) – A vulnerability that allows a Backup or Tape Operator to perform RCE as root by creating a malicious backup configuration file
  • CVE-2025-59468 (CVSS score: 6.7) – A vulnerability that allows a Backup Administrator to perform RCE as the postgres user by sending a malicious password parameter
  • CVE-2025-59469 (CVSS score: 7.2) – A vulnerability that allows a Backup or Tape Operator to write files as root

All four identified vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier versions of 13 builds. They have been addressed in Backup & Replication version 13.0.1.1071.

While Veeam makes no mention of the flaws being exploited in the wild, it’s essential that users promptly apply the fixes, given that vulnerabilities in the software have been exploited by threat actors in the past.



Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
The Future of Cybersecurity Includes Non-Human Employees

The Future of Cybersecurity Includes Non-Human Employees

Recommended.

Unilumin auf der WOO 2026 in London: Gestaltung einer intelligenteren und nachhaltigeren Zukunft für den globalen DOOH-Markt

Unilumin auf der WOO 2026 in London: Gestaltung einer intelligenteren und nachhaltigeren Zukunft für den globalen DOOH-Markt

June 13, 2026
Small Axe Delivers 0K in Savings for AI Computing Company Through Strategic Data Center Migration

Small Axe Delivers $800K in Savings for AI Computing Company Through Strategic Data Center Migration

March 13, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio