Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication
In order to fix many vulnerabilities in its Backup & Replication software, including a "critical" problem that might lead to remote code execution (RCE), Veeam has released security upgrades.
The vulnerability has a CVSS score of 9.0 and is tagged as CVE-2025-59470. According to a Tuesday notice, this vulnerability enables a Backup or Tape Operator to execute remote code execution (RCE) as the Postgres user by passing a malicious interval or order parameter.
A user with a Backup Operator role can start and stop running tasks, export backups, copy backups, and make VeeamZip backups, according to Veeam's documentation. In contrast, a user of Tape Operator has the ability to perform tape backup or catalog tasks, eject tapes, import and export tapes, move tapes to a media pool, copy...




