Veeam ONE with Critical Vulnerability CVE-2026-65641 (CVSS 9.3)

Sicherheit (Pexels, allgemeine Nutzung)[German]A brief update for users and administrators who rely on Veeam ONE. There is a critical vulnerability, CVE-2026-65641 (CVSS 9.3), in Veeam ONE that could potentially expose login credentials. Veeam ONE should therefore be updated immediately to versions 13.1.0.7233 or 13.0.2.7159.

I came across the information that Veeam published on August 25, 2026, in security advisory KB4905: Vulnerability Resolved in Veeam ONE 13.1 Patch 0 via the following tweet.

Veeam-One CVE-2026-65641

The critical vulnerability CVE-2026-65641 (CVSS 9.3) in Veeam ONE allows an unauthenticated network attacker to force the Veeam ONE service account to perform SMB authentication. This may result in the disclosure of NTLM credentials.

Affected versions include Veeam ONE 13.1.0.7034 and earlier. As of August 25, 2026, Veeam has released the following updates to address the vulnerability:

This entry was posted in issue, Security, Software and tagged , , , . Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

Note: Please note the rules for commenting on the blog (first comments and linked posts end up in moderation, I release them every few hours, I rigorously delete SEO posts/SPAM).