Veeam isn't used to protect anything important, right? So a sev:CRIT 9.9 RCE shouldn't be a big deal.
A vulnerability allowing remote code execution (RCE) by authenticated domain users.
But it's cool because they're going to blame it on their customers:
Note: This vulnerability only impacts domain-joined backup servers, which is against the Security & Compliance Best Practices.