Veeam has patched CVE-2026-65641, a critical (CVSS 9.3) unauthenticated network vulnerability in Veeam ONE 13 that can coerce SMB authentication attempts from the Veeam ONE service account. Attackers could capture Net-NTLM material for offline cracking or relay it to other services, creating a path to lateral movement and compromise of privileged backup infrastructure. Affected releases include Veeam ONE 13.1.0.7034 and earlier 13.x builds; legacy 12.x versions are not affected.
The fix is available in Veeam ONE 13.1 Patch 0 build 13.1.0.7233 and Veeam ONE 13.0.2 Patch 1 build 13.0.2.7159, detailed in advisory KB4905. Veeam also addressed a separate medium-severity issue in Veeam Backup & Replication that can write Application-Aware Processing guest OS credentials in cleartext to guest-machine logs. Neither issue is known to be exploited or has a public proof of concept; organizations should deploy the updates, restrict outbound SMB, harden systems against NTLM relay, and minimize privileges assigned to the Veeam ONE service account.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Veeam released KB4902 fixes for a medium-severity Veeam Backup & Replication vulnerability that could write Application-Aware Processing guest OS credentials in cleartext logs on guest machines. The issue affected version 13 builds through 13.0.2.29 and was remediated in builds 13.1.0.411 and 13.0.3.63.
Veeam published KB4905 and released fixes for CVE-2026-65641, a CVSS 9.3 unauthenticated SMB authentication-coercion flaw affecting Veeam ONE version 13 builds through 13.1.0.7034. The flaw was fixed in builds 13.1.0.7233 and 13.0.2.7159; Veeam stated it had been reported through HackerOne and had no confirmed in-the-wild exploitation or public proof of concept.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceheise.de
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.