Threat reportVulnerabilityTL-2026-3191
CVE-2025-64393: Critical Veeam Backup & Replication RCE via Mount Service Insecure Deserialization
CVE-2025-64393 (TL-2026-3191) is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-10-10. It has no confirmed attribution, affects Veeam Veeam Backup & Replication, references 1 CVE (CVE-2025-64393), maps to 5 MITRE ATT&CK techniques (T1059, T1078, T1485), and is covered by 9 detection rules and 7 indicators of compromise.
- CVSS
- 9.4/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-3191
- Threat ID
- TL-2026-3191
- Severity
- CRITICAL
- CVSS
- 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all sectors running veeam backup replication, enterprise it, managed service providers
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 7
How CVE-2025-64393 works
Insecure deserialization of untrusted data received via the Veeam Backup & Replication Mount Service lets a low-privileged authenticated user holding the Backup Viewer role execute arbitrary code (as SYSTEM per NVD) on the Veeam Backup Server. Affects version 12 builds up to and including 12.3.2.4854; fixed in 12.3.2 P4 (build 12.3.2.4934). Version 13 is not affected.
CVE-2025-64393 is a critical (CVSS v4.0 9.4) remote code execution vulnerability in Veeam Backup & Replication version 12. Per Veeam KB4934 and NVD, untrusted data received through the Mount Service can be insecurely deserialized (CWE-502), allowing a user with only the low-privileged Backup Viewer role to execute arbitrary code on the Veeam Backup Server. NVD describes the result as code execution as SYSTEM. The CVSS v4.0 vector (AV:N/AC:L/AT:N/PR:L/UI:N, VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) indicates a network-reachable, low-complexity attack requiring low privileges and no user interaction, with complete impact on the vulnerable and subsequent systems. The flaw was reported through HackerOne.
The Mount Service is the Veeam component that provides mount functionality (for example file-level restore mount points) and is deployed on the Veeam backup server, on the standalone console, and on managed servers assigned the mount server role. Public sources do not describe the precise deserialization gadget, endpoint or wire protocol, and no proof-of-concept has been publicly validated.
Affected: Veeam Backup & Replication 12.3.2 P3 (build 12.3.2.4854) and all earlier version 12 builds. Fixed in 12.3.2 P4 (build 12.3.2.4934), disclosed in Veeam KB4934 on 2026-10-06 together with CVE-2026-93026 (medium, CVSS 4.0 6.1: a Backup Viewer could modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials) and CVE-2025-64392 (medium, CVSS 4.0 4.8: reflected XSS in Veeam Backup Enterprise Manager). Version 13 is not vulnerable.
As of the sources reviewed (Veeam KB4934, NVD, SOC Prime, SecurityOnline), no in-the-wild exploitation has been reported and no threat actor, malware or network IOC is named; the CVE is not in the CISA KEV catalog as of 2026-10-08. Backup servers are nevertheless a high-value target class: compromise enables credential theft, backup tampering or destruction, and ransomware facilitation, and a prior Veeam deserialization RCE (CVE-2024-40711) was exploited by Akira, Fog and Frag ransomware operators. Defenders should patch, restrict Backup Viewer role assignment, segment backup infrastructure, and monitor Backup Viewer authentication correlated with Mount Service activity and unexpected child processes or command execution on the backup server.
MITRE ATT&CK techniques used in TL-2026-3191
Execution
T1059 Command and Scripting Interpreter
Initial Access
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery
Credential Access
Affected products and versions in CVE-2025-64393
- Veeam — Veeam Backup & Replication
Vulnerable versions: 12.3.2.4854 (12.3.2 P3) and all earlier version 12 builds
Fixed in: 12.3.2 P4 (build 12.3.2.4934); 13 (not affected)
Remediation for CVE-2025-64393
Patches
- Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934), Veeam KB4934
- Migrate to Veeam Backup & Replication 13 (not affected)
Immediate actions
- Upgrade Veeam Backup & Replication 12 to 12.3.2 P4 (build 12.3.2.4934) or later
- Review and restrict Backup Viewer role assignments
- Monitor Backup Viewer authentication events correlated with abnormal Mount Service activity
Workarounds
- No vendor workaround published; reduce exposure by limiting who holds the Backup Viewer role
Longer-term hardening
- Apply least-privilege access principles to Veeam roles
- Segment backup infrastructure from production systems
- Track suspicious process execution and unexpected child processes from Veeam components on backup servers
CVEs associated with CVE-2025-64393
CVE-2025-64393
Weaknesses (CWE) in CVE-2025-64393
Timeline of CVE-2025-64393
- Prior Veeam deserialization RCE CVE-2024-40711 added to CISA KEV after exploitation by Akira, Fog and Frag ransomware operators, illustrating attacker interest in Veeam servers
- Fix available in Veeam Backup & Replication 12.3.2 P4; version 13 confirmed unaffected
- Veeam publishes KB4934 disclosing CVE-2025-64393 (reported via HackerOne) and releases 12.3.2 P4 build 12.3.2.4934 alongside CVE-2026-93026 and CVE-2025-64392
- NVD publishes CVE-2025-64393 with CVSS v4.0 9.4 and CWE-502; status Awaiting Analysis
- CVE-2025-64393 not listed in the CISA KEV catalog (1,739 entries at the time)
- SOC Prime and SecurityOnline publish analyses; NVD record modified; no in-the-wild exploitation or validated PoC reported
- Threadlinqs research completed; no threat actor, malware or network IOCs identified in public sources
Sources cited for CVE-2025-64393
- Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 (KB4934)
- NVD - CVE-2025-64393
- CVE-2025-64393: Critical Veeam Backup & Replication RCE Vulnerability (SOC Prime)
- Veeam Backup Vulnerability CVE-2025-64393 (SecurityOnline)
- CVE-2025-64393 (The Hacker Wire)
- CISA Known Exploited Vulnerabilities Catalog
- Veeam Help Center - Mount Servers
- CISA adds Veeam Backup and Replication flaw CVE-2024-40711 to KEV (Security Affairs)
- Critical Vulnerability in Veeam Products Exploited by Ransomware Gangs (Cyble)
Detection coverage for TL-2026-3191
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3191 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.