CVE-2025-23120 is a critical remote code execution (RCE) vulnerability affecting Veeam Backup & Replication, allowing authenticated domain users to execute arbitrary code on backup servers. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and severe impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community discussion and media coverage, indicating high awareness and concern. Organizations are urged to apply the provided patch or mitigation (KB4724) immediately to prevent potential compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0.0.1402, < 12.3.1.1139CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Veeam Backup and Replication Insecure Deserialization (CVE-2025-23120)
Mar 24, 2026Veeam Backup and Replication Insecure Deserialization (CVE-2025-23120)
Mar 24, 2026Veeam Backup and Replication Insecure Deserialization (CVE-2025-23120)
Mar 24, 2026