Target Industry
Indiscriminate, opportunistic targeting.
Overview
A critical remote code execution (RCE) vulnerability has been identified in Veeam Backup & Replication software. It is tracked as CVE-2025-23121 with a CVSS score of 9.9, indicating a high severity level.
Impact
The impact of CVE-2025-23121 is profound, as it jeopardises the integrity of backup data and poses a significant threat to the overall security posture of organisations using Veeam Backup & Replication. Exploitation of this vulnerability could lead to unauthorised access, data manipulation, and operational disruptions, resulting in severe financial losses, reputational damage, and potential regulatory penalties.
Affected Products
Veeam Backup & Replication versions prior to 12.3.2.
Exploitation
The vulnerability can be exploited by authenticated domain users, allowing them to execute arbitrary code on Veeam Backup Servers. This exploitation can occur through low-complexity threat actors that require only standard domain user credentials. Threat actors may leverage this vulnerability to manipulate backup processes, delete critical data, or deploy ransomware, thereby exacerbating the impact of an already dire situation.
Containment, Mitigations & Remediations
To mitigate the risks associated with CVE-2025-23121, organisations should immediately apply the latest patches released by Veeam. Additional strategies include implementing strict access controls and utilising multi-factor authentication (MFA).
Threat Landscape
Veeam Backup & Replication has a large deployment footprint and is commonly targeted by threat actors, including ransomware groups. The threat landscape surrounding CVE-2025-23121 is characterised by increasing sophistication in cyber–attacks, particularly those targeting backup and recovery solutions. As organisations continue to rely on digital infrastructure, the potential for exploitation of vulnerabilities like CVE-2025-23121 grows, making it imperative for organisations to adopt proactive security measures.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information













