ZeroHour

CVE-2026-65641

large

Unauthenticated SMB Authentication Coercion in Veeam Software

CVSS 4.0
9.3 critical
EPSS
<1%p44
Published
()
Modified
AI analysis

CVE-2026-65641 is a critical (CVSS 4.0: 9.3) flaw, categorized as an authentication bypass (CWE-288), that lets an unauthenticated network attacker induce the affected Veeam product's service account to authenticate over SMB to an attacker-controlled host. The attack is triggered by network requests to the vulnerable service with no credentials, privileges, or user interaction required, per the CVSS vector (AV:N/AC:L/AT:N/PR:N/UI:N). Successful coercion exposes the service account's SMB/NTLM authentication to capture or relay, yielding high confidentiality impact on the vulnerable system and on subsequent systems that the service account can reach. Organizations running the affected Veeam software are exposed primarily to network-adjacent attackers; Veeam has released patches, though the specific product and version range are not stated in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a ~0.5% probability of exploitation within 30 days.

What to do: Apply the patches Veeam has released, consulting the vendor advisory for the exact fixed versions (not specified in the available data). Restrict network access to the affected service, run it under a service account with minimal privileges and limited reach to sensitive systems, and enforce SMB signing and NTLM relay protections to blunt coercion-style attacks. Check authentication logs for unexpected SMB authentication attempts originating from the service account.

Affected
Veeam
Estimated exposure
largeon the order of 100,000+ installations — Veeam's backup and infrastructure products are deployed across a very broad enterprise install base, so the affected product plausibly runs on the order of 100k+ systems, although the exact product and installed-base count cannot be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

Weakness
CWE-288
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Veeam Released Patches for Critical Vulnerability (CVE-2026-65641)

Veeam patched critical CVE-2026-65641 (CVSS 9.3) in Veeam ONE, exploitable by unauthenticated network attackers to coerce SMB authentication from the service account.

Veeam released patches for its Veeam ONE monitoring, reporting, and capacity planning software addressing CVE-2026-65641, rated critical with a CVSS score of 9.3. Successful exploitation allows an unauthenticated network attacker to coerce SMB authentication from the Veeam ONE service account, creating relay-style attack opportunities. Qualys ThreatPROTECT relayed the vendor advisory; administrators should apply the patches promptly. No in-the-wild exploitation is noted in the advisory.