Critical Veeam ONE Vulnerability Allows SMB Authentication Coercion

Critical Veeam ONE Vulnerability Allows SMB Authentication Coercion

First seen 27 Aug 2026, 17:53 UTC Gbhackerswww.veeam.com 60.6

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Veeam ONE, tracked as CVE-2026-65641, has been disclosed, allowing unauthenticated network attackers to coerce SMB authentication from the service account running the affected service. This vulnerability has been assigned a CVSS v4.0 score of 9.3, indicating its high severity. Veeam released security updates to address this issue, which was reported through HackerOne. Organizations using Veeam ONE are urged to apply the necessary patches to mitigate potential exploitation. The vulnerability was published in the knowledge base on August 26, 2026, and is currently being monitored for any signs of active exploitation. Failure to address this vulnerability could lead to unauthorized access and potential data breaches.

Key Points: • CVE-2026-65641 allows unauthenticated SMB authentication coercion. • The vulnerability has a critical CVSS score of 9.3. • Veeam has released patches to mitigate the vulnerability.

Timeline

2026-08-26
CVE-2026-65641 published
Veeam disclosed a critical vulnerability in Veeam ONE that allows SMB authentication coercion.
Gbhackers
2026-08-27
Veeam releases security updates
Patches were released to address the critical vulnerability in Veeam ONE, urging users to apply them immediately.
Veeam