CVE-2025-23114: Veeam Backup For Aws

Critical severity, CVSS 9.0. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.

Affected products

  • Veeam Backup For Aws: from 7.0, up to and including 7.0
  • Veeam Backup For Google Cloud: from 5.0, up to and including 5.0
  • Veeam Backup For Microsoft Azure: from 6.0, up to and including 6.0
  • Veeam Backup For Nutanix Ahv: from 5.1, up to and including 5.1
  • Veeam Backup For Oracle Linux Virtualization Manager And Red Hat Virtualization: from 4.1, up to and including 4.1
  • Veeam Backup For Salesforce: from 3.1, up to and including 3.1

Published 2025-02-05. Last modified 2026-06-17.