Veeam has released Veeam Backup & Replication 12.3.2 P4, build 12.3.2.4934, to address four security vulnerabilities, including a flaw that lets attackers execute malicious scripts in an authenticated user’s browser. Released on October 6, 2026, the update also fixes a critical remote code execution vulnerability affecting the backup server. The vulnerabilities carry CVSS 4.0 scores ranging from 4.8 to 9.4. They involve browser script execution, insecure deserialization, unauthorized access to sensitive configuration data, and arbitrary file reading. Although the weaknesses have different requirements, several involve authenticated accounts with limited privileges, making account permissions an important consideration for...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!