securityonline.info 8/26/2026, 9:47:12 AM · external

Veeam Patches Critical SMB Auth Flaw and Cleartext Credential Bug

Veeam Patches Critical SMB Auth Flaw and Cleartext Credential Bug
CyberSIXT Evidence Panel
Primary Source veeam.com
CISA KEV Not in KEV
Patch Patch Status Unknown

VEEAM has released patches for two vulnerabilities on August 25, 2026. The critical vulnerability, CVE-2026-65641, scores a CVSS of 9.3, allowing unauthenticated network attackers to coerce SMB authentication in Veeam ONE, posing a high risk. A second medium-severity bug involves guest OS credentials being logged in cleartext in Veeam Backup and Replication. While no active exploitation has been reported, both vulnerabilities should be addressed promptly by updating to the latest software versions. The affected versions include Veeam ONE 13.1.0.7034 and earlier, and Veeam Backup and Replication 13.0.2.29 and earlier.

View Primary Source Via securityonline.info

Article by CyberSIXT