Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Veeam ONE: Critical Vulnerability CVE-2026-65641 (CVSS 9.3) Disclosed

The monitoring solution Veeam ONE contains a critical vulnerability: CVE-2026-65641 is rated critical with a CVSS score of 9.3.

What it is about

As Borns IT- und Windows-Blog reports, the flaw disclosed on 25 August 2026 affects Veeam ONE version 13.1.0.7034 and earlier. Through the vulnerability, an unauthenticated network attacker can force the Veeam ONE service account to perform an SMB authentication. As a result, NTLM credentials may be disclosed, which can be abused for further attacks within the network.

These patches are available

Veeam has documented the security flaw in advisory KB4905 and released corrected builds. Administrators should update promptly:

  • Veeam ONE 13.1 Patch 0 (build 13.1.0.7233)
  • Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159)

What affected users should do

Given the high CVSS score of 9.3, applying the patches without delay is advisable. Anyone unable to update immediately should restrict network access to the Veeam ONE server and monitor outbound SMB connections from the service account.


Sources: Borns IT- und Windows-Blog.

Mastodon
Scroll to Top