CVE-2026-65641 (CVSS 9.3): Veeam ONE Flaw Lets Unauthenticated Attacker Coerce SMB Authentication
ID: b9bd844d-52f7-57a5-93ec-f85b1ea874e0
STIX ID: report--b9bd844d-52f7-57a5-93ec-f85b1ea874e0
Feed Name: securityonline.info
Threat Score
Veeam released patches for two vulnerabilities on August 25, 2026: a critical CVE-2026-65641 in Veeam ONE (CVSS 9.3) that allows unauthenticated SMB authentication coercion enabling credential capture and potential relay attacks, and a separate issue in Veeam Backup and Replication that records guest OS credentials in cleartext logs; affected builds and recommended patch versions are provided and Veeam reports no confirmed exploitation so far.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
