TL;DR
Veeam patched two flaws on August 25, 2026. The critical one, CVE-2026-65641, scores CVSS 9.3 and lets an unauthenticated network attacker coerce SMB authentication in Veeam ONE. A second, medium-severity bug affects Veeam Backup and Replication. Update both now.
Why This Veeam Vulnerability Matters
Veeam software protects backups across many enterprises. Attackers prize backup systems, since they hold the keys to recovery. This Veeam vulnerability set touches both monitoring and backup tools.
The critical bug carries a 9.3 score. Because it needs no login, the barrier to attack is low. As a result, exposed Veeam ONE servers face real risk.
How the Attacks Work
The main flaw lets an unauthenticated network attacker coerce SMB authentication from the service account. In practice, an attacker forces the server to authenticate to a system they control. That captured authentication can then feed relay attacks against other hosts.
The second bug is less severe. Veeam says it causes guest OS credentials for Application Aware processing to be recorded in cleartext in logs on the guest machine.
Consequently, anyone reading those logs could harvest credentials.
Is It Being Exploited?
No exploitation in the wild has been confirmed. Both bugs came through Veeam’s HackerOne program. Likewise, no public proof-of-concept exists yet.
Affected Versions
The SMB flaw affects Veeam ONE 13.1.0.7034 and all earlier version 13 builds. The credential-logging bug affects Veeam Backup and Replication 13.0.2.29 and earlier version 13 builds. Older 12.x releases are not affected.
Patch and Mitigation Steps
Update Veeam ONE to build 13.1.0.7233 or 13.0.2.7159, per the KB4905 advisory. For Backup and Replication, move to build 13.1.0.411 or 13.0.3.63, as noted in the KB4902 advisory. Attackers often reverse-engineer patches, so act quickly.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!