CVE-2025-48983: Veeam Backup & Replication

Critical severity, CVSS 9.9. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

Affected products

  • Veeam Veeam Backup & Replication: from 12.0.0.1402, before 12.3.2.4165 (fixed in 12.3.2.4165)

Published 2025-10-31. Last modified 2026-10-07.