Veeam security advisory (AV26-855)
Canada's Cyber Centre advisory AV26-855 says Veeam Backup & Replication and Veeam ONE vulnerabilities are resolved in 13.0.3 and 13.1 updates.
Advisory AV26-855, dated August 27, 2026, states that as of August 25 Veeam is affected by vulnerabilities in Backup & Replication (prior to 13.0.3 build 13.0.3.63 and prior to 13.1 build 13.1.0.411) and Veeam ONE (prior to or equal to 13.0.2.6723 and 13.1.0.7034). Fixes are documented in KB4902 (Veeam Backup & Replication 13.1) and KB4905 (Veeam ONE 13.1 Patch 0). The Cyber Centre urges users and administrators to apply the available updates. No CVE identifiers or exploitation details are given.
- Advisory AV26-855 covers Veeam Backup & Replication and Veeam ONE
- Fixes shipped in Veeam B&R 13.1 and Veeam ONE 13.1 Patch 0
- Admins urged to review KB4902 and KB4905 and patch
Serial Number: AV26-855 Date: August 27, 2026 As of August 25, 2026, Veeam is affected by vulnerabilities in the following products: Backup and Replication Prior to 13.0.3 (build 13.0.3.63) Prior to 13.1 (build 13.1.0.411) ONE Prior to or equal to 13.0.2.6723 Prior to or equal to 13.1.0.7034 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. KB4902: Vulnerability Resolved in Veeam Backup & Replication 13.1 KB4905: Vulnerability Resolved in Veeam ONE 13.1 Patch 0 Veeam Support Knowledge Base
This source does not provide full text. Read it at cyber.gc.ca.