CVE-2026-65641 is a critical vulnerability in Veeam ONE for Windows that permits an unauthenticated remote attacker to coerce SMB authentication by the Veeam ONE service account. The weakness is network-accessible, requires no attacker privileges or user interaction, and has low attack complexity. The underlying vulnerable component and the exact coercion mechanism have not been specified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated network-accessible vulnerability that allows an attacker to coerce SMB authentication from a service account. The content provides a CVSS v4 vector indicating high confidentiality impact and low integrity impacts across vulnerable and subsequent systems.
A critical CVSS 9.3 unauthenticated network vulnerability in Veeam ONE that permits coercion of SMB authentication from the service account, potentially enabling captured-authentication relay attacks against other hosts.
A critical, network-accessible Veeam ONE vulnerability that requires no privileges or user interaction and can compromise confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.