Vulnerability intelligence
CVE-2025-23121
Veeam Backup and Recovery
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVSS Score
9.9
Critical
EPSS — Exploit Probability
22%
Riskier than 98% of all CVEs · checked 2026-09-08
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jun 9, 2026 · latest Jun 9, 2026
Coverage timeline
-
Veeam patches critical RCE in Backup & Replication 12.xsecurityaffairs.com · Jun 9, 2026