TL;DR
Veeam patched a maximum-severity Veeam ONE vulnerability. CVE-2026-64633 allows remote unauthenticated code execution and scores a perfect CVSS 10.0. Admins should update to build 13.1.0.7034 right away.
Why it matters
Veeam ONE monitors backup and virtualization health across the enterprise. So it sits deep inside critical infrastructure. The flaw enables remote code execution with no login at all. This Veeam ONE vulnerability needs no password and no user interaction. Because Veeam products are frequent ransomware targets, the stakes rise further. Attackers prize backup and monitoring tools, since they hold the keys to recovery. A foothold here can disable defenses before a ransomware strike.
How the attack works
Veeam describes CVE-2026-64633 as “a vulnerability allowing remote unauthenticated code execution on the agent host.” An attacker reaches the agent over the network and runs code without logging in. The agent runs on monitored systems, so exposure can be broad. A single reachable agent could hand over a foothold. The vendor has not shared deeper technical details. Veeam also reported no exploitation in the wild, and no public proof-of-concept has surfaced.
Other fixes in this release
The same update resolves five more flaws. CVE-2026-58075 lets an unauthenticated attacker read arbitrary files, rated CVSS 8.7. CVE-2026-58074 and CVE-2026-64631 allow code execution and SQL injection by privileged or low-privileged users, both at 8.6. CVE-2026-64634 grants local privilege escalation at 8.4. Finally, CVE-2026-64630 exposes shared report data at 5.3.
Affected versions
The Veeam ONE vulnerability set affects version 13.0.2.6723 and all earlier version 13 builds.
Patch and mitigation
Update to Veeam ONE 13.1.0.7034, which contains every fix. There is no standalone workaround. Until you patch, restrict network access to Veeam ONE agents. Then confirm every host runs the fixed build. For full details, read Veeam’s KB4892 advisory.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.