Veeam has released security updates for two critical vulnerabilities across Veeam ONE and Veeam Service Provider Console. Both flaws are remotely exploitable without authentication. Successful exploitation could lead to remote code execution on a Veeam ONE agent host or the theft of credentials belonging to a managed Service Provider Console agent.
Affected: Veeam ONE 13.0.2.6723 and all earlier version 13 builds
Fixed: Veeam ONE 13.1.0.7034
Not affected: Veeam has not published a separate unaffected-version or configuration statement.
Source: Veeam ONE 13.1 security advisory
Affected: Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds
Fixed: Veeam Service Provider Console 9.3.0.35057
Not affected: Veeam has not published a separate unaffected-version or configuration statement.
Source: Veeam Service Provider Console 9.3 security advisory
CVSS: 10.0, CVSS v4.0
Published: 29 July 2026
Description: CVE-2026-64633 allows a remote, unauthenticated attacker to execute code on the Veeam ONE agent host.
Impact: Successful exploitation can compromise the confidentiality, integrity and availability of the agent host and connected systems.
Conditions: No authentication or user interaction is required. The affected service must be network reachable.
Action: Upgrade to Veeam ONE 13.1.0.7034.
Product: Veeam Service Provider Console
Published: 4 August 2026
Description: CVE-2026-58073 allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials.
Impact: Successful exploitation can expose managed-agent credentials and compromise access associated with that agent.
Conditions: No authentication or user interaction is required. Veeam rates attack complexity as high.
Action: Upgrade to Veeam Service Provider Console 9.3.0.35057.
Upgrade Veeam ONE to version 13.1.0.7034.
Upgrade Veeam Service Provider Console to version 9.3.0.35057.
Prioritise internet-facing or otherwise untrusted-network-accessible systems.
Review affected hosts and managed-agent accounts for unexpected access or activity.
Veeam has not published a workaround for either vulnerability. Applying the fixed builds is the required remediation.
Products: Veeam ONE and Veeam Service Provider Console
Threat Level: Critical, CVSS 10.0 and 9.5
Action Required: Upgrade Veeam ONE to 13.1.0.7034 and Veeam Service Provider Console to 9.3.0.35057 immediately. Review exposed systems and associated agent credentials for suspicious activity.
Veeam ONE 13.1 security advisory
Veeam ONE build numbers and release history
Veeam ONE 13 release information
Veeam Service Provider Console 9.3 security advisory
Veeam Service Provider Console security fixes
Veeam Service Provider Console 9 release history
CVE Program record for CVE-2026-64633
CVE Program record for CVE-2026-58073
Secure ISS can assist with exposure assessment, upgrade planning and post-update validation. the Secure ISS SOC team on 1300 769 460.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
