Veeam Released Patches for Critical Vulnerability (CVE-2026-65641)

Veeam released a security advisory addressing a vulnerability affecting Veeam ONE. Tracked as CVE-2026-65641, the vulnerability has a critical severity rating with a CVSS score of 9.3. Successful exploitation of the vulnerability may allow an unauthenticated network attacker to coerce SMB authentication from the service account.

Veeam ONE is a monitoring, reporting, and capacity planning software for virtual, physical, and backup environments. It integrates with platforms like Veeam Backup & Replication, VMware vSphere, and Microsoft Hyper-V to give IT teams deep visibility, automated alerts, and compliance tracking.

Affected Versions

The vulnerability affects Veeam ONE 13.1.0.7034 and all earlier versions 13 builds.

Mitigation

Users must upgrade to the following versions to patch the vulnerability:

  • Veeam ONE 13.1 Patch 0 (build 13.1.0.7233)
  • Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159)

Please refer to the Veeam Security Advisory (KB4905) for more information.

Qualys Detection

Qualys customers can scan their devices with QID 388537 to detect vulnerable assets.

Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.

References
https://www.veeam.com/kb4905