AI analysis
CVE-2026-65641 is a critical (CVSS 4.0: 9.3) flaw, categorized as an authentication bypass (CWE-288), that lets an unauthenticated network attacker induce the affected Veeam product's service account to authenticate over SMB to an attacker-controlled host. The attack is triggered by network requests to the vulnerable service with no credentials, privileges, or user interaction required, per the CVSS vector (AV:N/AC:L/AT:N/PR:N/UI:N). Successful coercion exposes the service account's SMB/NTLM authentication to capture or relay, yielding high confidentiality impact on the vulnerable system and on subsequent systems that the service account can reach. Organizations running the affected Veeam software are exposed primarily to network-adjacent attackers; Veeam has released patches, though the specific product and version range are not stated in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a ~0.5% probability of exploitation within 30 days.
What to do: Apply the patches Veeam has released, consulting the vendor advisory for the exact fixed versions (not specified in the available data). Restrict network access to the affected service, run it under a service account with minimal privileges and limited reach to sensitive systems, and enforce SMB signing and NTLM relay protections to blunt coercion-style attacks. Check authentication logs for unexpected SMB authentication attempts originating from the service account.
Estimated exposure
largeon the order of 100,000+ installations — Veeam's backup and infrastructure products are deployed across a very broad enterprise install base, so the affected product plausibly runs on the order of 100k+ systems, although the exact product and installed-base count cannot be…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.