www.veeam.com
Critical Veeam ONE Vulnerability Allows SMB Authentication Coercion
Article Content
A critical vulnerability in Veeam ONE, tracked as CVE-2026-65641, has been disclosed, allowing unauthenticated network attackers to coerce SMB authentication from the service account running the affected service. This vulnerability has been assigned a CVSS v4.0 score of 9.3, indicating its high severity. Veeam released security updates to address this issue, which was reported through HackerOne. Organizations using Veeam ONE are urged to apply the necessary patches to mitigate potential exploitation. The vulnerability was published in the knowledge base on August 26, 2026, and is currently being monitored for any signs of active exploitation. Failure to address this vulnerability could lead to unauthorized access and potential data breaches.
Key Points: • CVE-2026-65641 allows unauthenticated SMB authentication coercion. • The vulnerability has a critical CVSS score of 9.3. • Veeam has released patches to mitigate the vulnerability.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.