CVE-2025-64392: Veeam Backup Enterprise Manager

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link.

Affected products

  • Veeam Backup Enterprise Manager: from 12, before 12.3.2.4934 (fixed in 12.3.2.4934)

Published 2026-10-07. Last modified 2026-10-07.