CVE-2025-32406: NAKIVO Backup & Replication Director

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.

Affected products

  • NAKIVO Backup & Replication Director: from 10.3, before 11.0.2 (fixed in 11.0.2)

Published 2025-04-08. Last modified 2026-06-17.