Threat reportVulnerabilityTL-2026-3191

CVE-2025-64393: Critical Veeam Backup & Replication RCE via Mount Service Insecure Deserialization

criticalPATCHED

CVE-2025-64393 (TL-2026-3191) is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-10-10. It has no confirmed attribution, affects Veeam Veeam Backup & Replication, references 1 CVE (CVE-2025-64393), maps to 5 MITRE ATT&CK techniques (T1059, T1078, T1485), and is covered by 9 detection rules and 7 indicators of compromise.

CVSS
9.4/10Critical
CVEs
1Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-3191

Threat ID
TL-2026-3191
Severity
CRITICAL
CVSS
9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all sectors running veeam backup replication, enterprise it, managed service providers
Target regions
Global
Detection rules
9
Indicators of compromise
7

How CVE-2025-64393 works

Insecure deserialization of untrusted data received via the Veeam Backup & Replication Mount Service lets a low-privileged authenticated user holding the Backup Viewer role execute arbitrary code (as SYSTEM per NVD) on the Veeam Backup Server. Affects version 12 builds up to and including 12.3.2.4854; fixed in 12.3.2 P4 (build 12.3.2.4934). Version 13 is not affected.

CVE-2025-64393 is a critical (CVSS v4.0 9.4) remote code execution vulnerability in Veeam Backup & Replication version 12. Per Veeam KB4934 and NVD, untrusted data received through the Mount Service can be insecurely deserialized (CWE-502), allowing a user with only the low-privileged Backup Viewer role to execute arbitrary code on the Veeam Backup Server. NVD describes the result as code execution as SYSTEM. The CVSS v4.0 vector (AV:N/AC:L/AT:N/PR:L/UI:N, VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) indicates a network-reachable, low-complexity attack requiring low privileges and no user interaction, with complete impact on the vulnerable and subsequent systems. The flaw was reported through HackerOne.

The Mount Service is the Veeam component that provides mount functionality (for example file-level restore mount points) and is deployed on the Veeam backup server, on the standalone console, and on managed servers assigned the mount server role. Public sources do not describe the precise deserialization gadget, endpoint or wire protocol, and no proof-of-concept has been publicly validated.

Affected: Veeam Backup & Replication 12.3.2 P3 (build 12.3.2.4854) and all earlier version 12 builds. Fixed in 12.3.2 P4 (build 12.3.2.4934), disclosed in Veeam KB4934 on 2026-10-06 together with CVE-2026-93026 (medium, CVSS 4.0 6.1: a Backup Viewer could modify or delete the Enterprise Manager master key and read or overwrite stored antivirus update credentials) and CVE-2025-64392 (medium, CVSS 4.0 4.8: reflected XSS in Veeam Backup Enterprise Manager). Version 13 is not vulnerable.

As of the sources reviewed (Veeam KB4934, NVD, SOC Prime, SecurityOnline), no in-the-wild exploitation has been reported and no threat actor, malware or network IOC is named; the CVE is not in the CISA KEV catalog as of 2026-10-08. Backup servers are nevertheless a high-value target class: compromise enables credential theft, backup tampering or destruction, and ransomware facilitation, and a prior Veeam deserialization RCE (CVE-2024-40711) was exploited by Akira, Fog and Frag ransomware operators. Defenders should patch, restrict Backup Viewer role assignment, segment backup infrastructure, and monitor Backup Viewer authentication correlated with Mount Service activity and unexpected child processes or command execution on the backup server.

MITRE ATT&CK techniques used in TL-2026-3191

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery

Credential Access

T1555 Credentials from Password Stores

Affected products and versions in CVE-2025-64393

  • Veeam — Veeam Backup & Replication
    Vulnerable versions: 12.3.2.4854 (12.3.2 P3) and all earlier version 12 builds
    Fixed in: 12.3.2 P4 (build 12.3.2.4934); 13 (not affected)

Remediation for CVE-2025-64393

Patches

  • Veeam Backup & Replication 12.3.2 P4 (build 12.3.2.4934), Veeam KB4934
  • Migrate to Veeam Backup & Replication 13 (not affected)

Immediate actions

  • Upgrade Veeam Backup & Replication 12 to 12.3.2 P4 (build 12.3.2.4934) or later
  • Review and restrict Backup Viewer role assignments
  • Monitor Backup Viewer authentication events correlated with abnormal Mount Service activity

Workarounds

  • No vendor workaround published; reduce exposure by limiting who holds the Backup Viewer role

Longer-term hardening

  • Apply least-privilege access principles to Veeam roles
  • Segment backup infrastructure from production systems
  • Track suspicious process execution and unexpected child processes from Veeam components on backup servers

CVEs associated with CVE-2025-64393

CVE-2025-64393

Weaknesses (CWE) in CVE-2025-64393

CWE-502

Timeline of CVE-2025-64393

  • Prior Veeam deserialization RCE CVE-2024-40711 added to CISA KEV after exploitation by Akira, Fog and Frag ransomware operators, illustrating attacker interest in Veeam servers
  • Fix available in Veeam Backup & Replication 12.3.2 P4; version 13 confirmed unaffected
  • Veeam publishes KB4934 disclosing CVE-2025-64393 (reported via HackerOne) and releases 12.3.2 P4 build 12.3.2.4934 alongside CVE-2026-93026 and CVE-2025-64392
  • NVD publishes CVE-2025-64393 with CVSS v4.0 9.4 and CWE-502; status Awaiting Analysis
  • CVE-2025-64393 not listed in the CISA KEV catalog (1,739 entries at the time)
  • SOC Prime and SecurityOnline publish analyses; NVD record modified; no in-the-wild exploitation or validated PoC reported
  • Threadlinqs research completed; no threat actor, malware or network IOCs identified in public sources

Sources cited for CVE-2025-64393

Detection coverage for TL-2026-3191

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3191 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats