VEEAM has released patches for two vulnerabilities on August 25, 2026. The critical vulnerability, CVE-2026-65641, scores a CVSS of 9.3, allowing unauthenticated network attackers to coerce SMB authentication in Veeam ONE, posing a high risk. A second medium-severity bug involves guest OS credentials being logged in cleartext in Veeam Backup and Replication. While no active exploitation has been reported, both vulnerabilities should be addressed promptly by updating to the latest software versions. The affected versions include Veeam ONE 13.1.0.7034 and earlier, and Veeam Backup and Replication 13.0.2.29 and earlier.
Veeam Patches Critical SMB Auth Flaw and Cleartext Credential Bug
CyberSIXT Evidence Panel
Article by CyberSIXT