Skip to content
Veeam Critical Vulnerabilities

Veeam Critical Vulnerabilities

Secure-Iss August 5, 2026

Veeam has released security updates for two critical vulnerabilities across Veeam ONE and Veeam Service Provider Console. Both flaws are remotely exploitable without authentication. Successful exploitation could lead to remote code execution on a Veeam ONE agent host or the theft of credentials belonging to a managed Service Provider Console agent.

Affected: Veeam ONE 13.0.2.6723 and all earlier version 13 builds

Fixed: Veeam ONE 13.1.0.7034

Not affected: Veeam has not published a separate unaffected-version or configuration statement.

Source: Veeam ONE 13.1 security advisory

Affected: Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds

Fixed: Veeam Service Provider Console 9.3.0.35057

Not affected: Veeam has not published a separate unaffected-version or configuration statement.

Source: Veeam Service Provider Console 9.3 security advisory

CVSS: 10.0, CVSS v4.0

Published: 29 July 2026

Description: CVE-2026-64633 allows a remote, unauthenticated attacker to execute code on the Veeam ONE agent host.

Impact: Successful exploitation can compromise the confidentiality, integrity and availability of the agent host and connected systems.

Conditions: No authentication or user interaction is required. The affected service must be network reachable.

Action: Upgrade to Veeam ONE 13.1.0.7034.

Product: Veeam Service Provider Console

Published: 4 August 2026

Description: CVE-2026-58073 allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials.

Impact: Successful exploitation can expose managed-agent credentials and compromise access associated with that agent.

Conditions: No authentication or user interaction is required. Veeam rates attack complexity as high.

Action: Upgrade to Veeam Service Provider Console 9.3.0.35057.

Upgrade Veeam ONE to version 13.1.0.7034.

Upgrade Veeam Service Provider Console to version 9.3.0.35057.

Prioritise internet-facing or otherwise untrusted-network-accessible systems.

Review affected hosts and managed-agent accounts for unexpected access or activity.

Veeam has not published a workaround for either vulnerability. Applying the fixed builds is the required remediation.

Products: Veeam ONE and Veeam Service Provider Console

Threat Level: Critical, CVSS 10.0 and 9.5

Action Required: Upgrade Veeam ONE to 13.1.0.7034 and Veeam Service Provider Console to 9.3.0.35057 immediately. Review exposed systems and associated agent credentials for suspicious activity.

Veeam ONE 13.1 security advisory

Veeam ONE build numbers and release history

Veeam ONE 13 release information

Veeam Service Provider Console 9.3 security advisory

Veeam Service Provider Console security fixes

Veeam Service Provider Console 9 release history

CVE Program record for CVE-2026-64633

CVE Program record for CVE-2026-58073

Secure ISS can assist with exposure assessment, upgrade planning and post-update validation. the Secure ISS SOC team on 1300 769 460.

Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.