Veeam Backup & Replication, used by many enterprises in their data protection strategies, has reportedly become the focus of a new exploit being offered for sale on the dark web.

According to a recent posting, a vendor with the alias “SebastianPereiro” claims to have a exploit remote code execution targeting specific versions of Veeam 12.x. It is called “Bug of June 2025” and is said to bypass standard authentication mechanisms and provide complete control over the server. Initial indications are that the exploit is linked to the CVE-2025-23121, although no official proof-of-concept exploit has been published.
See also: Critical vulnerabilities in VMware vCenter and NSX
Exploit for Veeam vulnerability
According to the dark web advertisement, successful exploitation only requires any valid Active Directory account, significantly reducing the difficulty levels for perpetrators who have obtained domain credentials through phishing or other lateral movement techniques.
The payment is set at $7,000 in cryptocurrency, with interested buyers being asked to send a private message to the seller.
While the absence of a public proof-of-concept limits independent verification, the potential impact of such an exploit on a backup infrastructure is large. Compromised systems could be used to extract, encrypt, or permanently destroy backups . ThreatMon analysts noted that enterprises running Veeam Backup & Replication in mixed Windows-Linux environments may be particularly vulnerable due to differences in logging and update management workflows.

Organizations that delay updates increase the risk of a successful breach.
See also: Vulnerability in Apple Font Parser affects applications
In response, security teams are urged to prioritize auditing Active Directory accounts with elevated privileges, verify update levels on all Veeam servers, and monitor for abnormal use of service accounts.
The exploit appears to leverage improper login validation in Veeam's REST API endpoint. An attacker authenticates with any AD account and submits a specially crafted JSON payload to the /api/sessions/startBackup endpoint, injecting shell commands directly into the backup session creation logic. Continuous monitoring of API traffic and security of AD accounts are critical to detecting and preventing this attack vector.
The possibility of a functional exploit in backup platforms requires strategy data protection — not just technical “patches.” Beyond the technical risk of exploiting critical services, the real problem for businesses is systemic dependency: backup solutions often have elevated privileges, connections to production systems, and access to sensitive files. This means that a successful attack on such a platform can instantly turn into the destruction or theft of entire corporate data stores.
See also: Datzbro: New Android trojan scams elderly people

At the risk management level, there is a need to immediately prioritize relevant assets within the framework of a “critical asset mapping” program: which servers and accounts have backup authorizations, which service accounts can modify or delete snapshots, and how data is recovered in the event of malicious manipulation. In addition, organizations should re-evaluate isolation models — immutable and air-gapped copies, distinct network rules for management planes, as well as policies that prevent the automatic removal of old copies.
From an operational perspective, detection should combine telemetry from the API layer with behavioral analytics: unusual backup job sequences, unexpected data exports, or changes to schedules should trigger immediate investigations. Organizations with mature incident response plans will incorporate tabletop exercises specifically for scenarios where the backups themselves have been compromised—this reveals gaps in recovery and communication processes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, at the administrative level, transparency: supplier notification, documentation of compliance actions, and communication with stakeholders. Investing in recovery planning — not just patches — will be the real antidote to these types of threats.
