DEV Community

Cover image for Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Veeam Patches Critical Authentication Coercion Flaw in Veeam ONE

Summary

Veeam released patches for a critical vulnerability (CVE-2026-65641) in Veeam ONE that allows unauthenticated attackers to steal service account NTLM credentials via SMB coercion. The flaw affects version 13 builds and could lead to unauthorized access to backup infrastructure.

Take Action:

If you're running Veeam ONE version 13.1.0.7034 or any earlier version 13 build, update ASAP to 13.1.0.7233 or 13.0.2.7159. This flaw lets attackers steal your service account credentials without logging in. After updating, review your network logs for any unusual SMB traffic coming from your Veeam servers, as this could indicate the flaw was already exploited.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)