Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks

Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks

First seen 5 Aug 2026, 19:31 UTC Veeamwww.veeam.com 85% similarity 78.0

Article Content

Browse articles
ThreatCluster

On August 5, 2026, Veeam disclosed multiple critical vulnerabilities affecting Veeam ONE and Veeam Service Provider Console. The vulnerabilities include remote unauthenticated code execution, file read access, and SQL injection, with CVSS scores ranging from 8.4 to 10.0. Affected systems include Veeam ONE 13.1 and the Veeam Service Provider Console, which could allow attackers to execute arbitrary code, impersonate agents, and exhaust host memory. These vulnerabilities were reported through HackerOne and discovered during internal testing. Patches have been released to address these issues, and users are urged to update their systems immediately.

Key Points: • Multiple critical vulnerabilities in Veeam software allow remote code execution and credential theft. • CVSS scores range from 8.4 to 10.0, indicating high severity and potential for exploitation. • Users are advised to apply patches immediately to mitigate risks associated with these vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-08-05
Veeam discloses vulnerabilities
Veeam announced critical vulnerabilities in Veeam ONE and Service Provider Console, affecting remote code execution and credential theft.
Veeam
2026-08-05
Patches released
Veeam released patches to fix the identified vulnerabilities, urging users to update their systems immediately.
Veeam

Community

Browse all →