ZeroHour
Organization

Veeam

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Veeam Released Patches for Critical Vulnerability (CVE-2026-65641)

Veeam patched critical CVE-2026-65641 (CVSS 9.3) in Veeam ONE, exploitable by unauthenticated network attackers to coerce SMB authentication from the service account.

Veeam released patches for its Veeam ONE monitoring, reporting, and capacity planning software addressing CVE-2026-65641, rated critical with a CVSS score of 9.3. Successful exploitation allows an unauthenticated network attacker to coerce SMB authentication from the Veeam ONE service account, creating relay-style attack opportunities. Qualys ThreatPROTECT relayed the vendor advisory; administrators should apply the patches promptly. No in-the-wild exploitation is noted in the advisory.

Related CVEs

  • Unauthenticated SMB Authentication Coercion in Veeam Software
    CVE-2026-65641 is a critical (CVSS 4.0: 9.3) flaw, categorized as an authentication bypass (CWE-288), that lets an unauthenticated network attacker induce the affected Veeam product's service account to authenticate over SMB to an attacker-controlled host. The attack is triggered by network requests to the vulnerable service with no credentials, privileges, or user interaction required, per the CVSS vector (AV:N/AC:L/AT:N/PR:N/UI:N). Successful coercion exposes the service account's SMB/NTLM authentication to capture or relay, yielding high confidentiality impact on the vulnerable system and on subsequent systems that the service account can reach. Organizations running the affected Veeam software are exposed primarily to network-adjacent attackers; Veeam has released patches, though the specific product and version range are not stated in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a ~0.5% probability of exploitation within 30 days.
    · Veeamlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.