Veeam Released Patches for Critical Vulnerability (CVE-2026-65641)
Veeam patched critical CVE-2026-65641 (CVSS 9.3) in Veeam ONE, exploitable by unauthenticated network attackers to coerce SMB authentication from the service account.
Veeam released patches for its Veeam ONE monitoring, reporting, and capacity planning software addressing CVE-2026-65641, rated critical with a CVSS score of 9.3. Successful exploitation allows an unauthenticated network attacker to coerce SMB authentication from the Veeam ONE service account, creating relay-style attack opportunities. Qualys ThreatPROTECT relayed the vendor advisory; administrators should apply the patches promptly. No in-the-wild exploitation is noted in the advisory.
- CVE-2026-65641 scored 9.3 (critical)
- No authentication required for exploitation
- SMB coercion exposes service account credentials to relay
- Affects Veeam ONE monitoring/reporting product
- Patches released - update Veeam ONE deployments
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65641 | Unauthenticated SMB Authentication Coercion in Veeam Software CVE-2026-65641 is a critical (CVSS 4.0: 9.3) flaw, categorized as an authentication bypass (CWE-288), that lets an unauthenticated network attacker induce the affected Veeam product's service account to authenticate over SMB to an attacker-controlled host. The attack is triggered by network requests to the vulnerable service with no credentials, privileges, or user interaction required, per the CVSS vector (AV:N/AC:L/AT:N/PR:N/UI:N). Successful coercion exposes the service account's SMB/NTLM authentication to capture or relay, yielding high confidentiality impact on the vulnerable system and on subsequent systems that the service account can reach. Organizations running the affected Veeam software are exposed primarily to network-adjacent attackers; Veeam has released patches, though the specific product and version range are not stated in the available data. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a ~0.5% probability of exploitation within 30 days. Do: Apply the patches Veeam has released, consulting the vendor advisory for the exact fixed versions (not specified in the available data). Restrict network access to the affected service, run it under a service account with minimal privileges and limited reach to sensitive systems, and enforce SMB signing and NTLM relay protections to blunt coercion-style attacks. Check authentication logs for unexpected SMB authentication attempts originating from the service account. | 9.3 | <1% |
| largeon the order of 100,000+ installations |
Veeam released a security advisory addressing a vulnerability affecting Veeam ONE. Tracked as CVE-2026-65641, the vulnerability has a critical severity rating with a CVSS score of 9.3. Successful exploitation of the vulnerability may allow an unauthenticated network attacker to coerce SMB authentication from the service account. Veeam ONE is a monitoring, reporting, and capacity planning software … Continue reading "Veeam Released Patches for Critical Vulnerability (CVE-2026-65641)"
This source does not provide full text. Read it at threatprotect.qualys.com.