CVE-2025-24286: Veeam Backup & Replication

Medium severity, CVSS 4.9. EPSS: 19.1% chance of exploitation in the next 30 days.

A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.

Affected products

  • Veeam Veeam Backup & Replication: before 12.3.2.3617 (fixed in 12.3.2.3617)

Published 2025-06-19. Last modified 2026-06-17.