Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026011210010303 | Publication Time | 2026/01/12 10:51 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/01/12 10:51 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Veeam Backup & Replication (CVE-2025-59470) |
|||
| [Content] Forwarded from TWCERTCC-200-202601-00000004 Veeam Backup & Replication is Veeam’s core backup software. Recently, Veeam released a critical security advisory for this vulnerability (CVE-2025-59470, CVSS: 9.0). This vulnerability allows a Backup or Tape Operator to send malicious interval or order parameters to achieve remote code execution (RCE) as the postgres user. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] Veeam Backup & Replication version 13 up to and including 13.0.1.180 |
|||
| [Recommended Actions] Update Veeam Backup & Replication to version 13.0.1.1071 or later. |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10618-1b9d3-1.html |
|||