Veeam released a patch to a 9.9/10 -swarming error that can lead to RCE
It was found in Veeam Backup & Restoration
The error only works on installations connected to a domain
VEEAM released a patch for a vulnerability at the critical level recently discovered in its backup & replication software.
The vulnerability traced as CVE-2025-23120 is described as a deserialization error that allows approved domain users to perform Remote Code Execution (RCE) attack. It got a severity of 9.9/10 (critical) and affects VEEAM BACKUP & REPLICATION 12.3.0.310 and all previous version 12 buildings.