Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Authentication From Service Accounts
ID: f2a11e78-8618-5816-9e50-c4c4cecfcfa6
STIX ID: report--f2a11e78-8618-5816-9e50-c4c4cecfcfa6
Feed Name: GBHackers
Threat Score
Veeam published security updates for a critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) that allows unauthenticated attackers with network access to coerce SMB/Net-NTLM authentication from the service account; affected Veeam ONE 13.1.0.7034 and earlier 13.x builds were fixed in 13.1 Patch 0 (13.1.0.7233) and 13.0.2 Patch 1 (13.0.2.7159).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
