Story perspectives
Veeam Urges Immediate Update for Critical Security Flaw
1/7/2026
40 5
1 of 1
Story summary
- Veeam issued security updates for Backup & Replication to fix a critical vulnerability, CVE-2025-59470 (CVSS 9.0), that could allow remote code execution as the postgres user by sending malicious parameters, and affects users with Backup or Tape Operator roles.
- The update also fixes three additional vulnerabilities with lower CVSS scores.
- Veeam urges users to apply the fixes promptly since past vulnerabilities have been exploited by attackers.
