Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AD Misconfigurations Enable Stealthy Kerberoasting Attacks
August 28, 2026
Critical cPanel Vulnerability (CVE-2023-XXXX) Allows Full Server Control
August 28, 2026
Critical PaperCut NG/MF Vulnerability Actively Exploited in Attacks
August 28, 2026
Home/CyberSecurity News/Critical Veeam Backup & Replication Flaw Exposes Guest OS Credentials
CyberSecurity News

Critical Veeam Backup & Replication Flaw Exposes Guest OS Credentials

Key Takeaways A critical vulnerability (CVE-2026-65641) in Veeam ONE 13 allows remote, unauthenticated attackers to force SMB authentication from the service account. This flaw could expose Net-NTLM...

Marcus Rodriguez
Marcus Rodriguez
August 27, 2026 3 Min Read
9 0

Key Takeaways

  • A critical vulnerability (CVE-2026-65641) in Veeam ONE 13 allows remote, unauthenticated attackers to force SMB authentication from the service account.
  • This flaw could expose Net-NTLM credentials, enabling attackers to crack passwords, relay authentication, or escalate privileges.
  • Veeam ONE 13.1.0.7034 and all prior Veeam ONE 13 builds are affected, but legacy 12.x releases are not.
  • Patches are available, and immediate upgrades to Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) or Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159) are advised.

Veeam ONE Flaw Exposes Critical Credentials

Veeam has issued a critical security advisory concerning a significant vulnerability within its Veeam ONE 13 monitoring solution. This flaw, identified as CVE-2026-65641, could allow an attacker operating remotely and without prior authentication to compel the product’s service account into an SMB authentication attempt.

Table Of Content

  • Key Takeaways
  • Veeam ONE Flaw Exposes Critical Credentials
  • Affected Versions and Impact
  • Available Fixes and Mitigation
  • What You Should Do

The severity of this issue is underscored by its CVSS v4.0 score of 9.3. The vulnerability was brought to Veeam’s attention via the HackerOne bug bounty program.

Affected Versions and Impact

The vulnerability specifically impacts Veeam ONE 13.1.0.7034 and all earlier builds within the Veeam ONE 13 series. Importantly, Veeam has confirmed that previous 12.x versions of the software are not susceptible to this particular flaw.

CVE-2026-65641 arises from a condition where an unauthenticated remote adversary can trigger an SMB authentication attempt originating from the Veeam ONE service account. In Windows environments, such authentication coercion vulnerabilities are particularly dangerous. They can lead to the exposure of Net-NTLM authentication material to a server controlled by the attacker.

Once captured, this authentication data can be exploited in several ways: an attacker might attempt offline password cracking, relay the captured credentials to another service to gain unauthorized access, or leverage the service account’s permissions to penetrate deeper into the network infrastructure.

The extent of potential damage hinges on the configuration of the Veeam ONE service account. Factors such as whether it possesses elevated privileges, access to backup infrastructure components, or broad permissions within Active Directory environments will dictate the severity of a compromise. This vulnerability is especially critical for organizations that rely on Veeam ONE for monitoring their backup and virtual environments, which frequently house highly privileged accounts, sensitive storage credentials, hypervisor access, and disaster recovery systems.

Full details regarding this vulnerability are available in the Veeam Knowledge Base article 4905, published on August 25, 2026. A successful compromise of a monitoring service account could provide attackers with a direct route to critical backup administration systems.

Available Fixes and Mitigation

Veeam has promptly released patches to address this vulnerability. Organizations currently operating Veeam ONE 13.1 should upgrade to Veeam ONE 13.1 Patch 0, build 13.1.0.7233. For those running Veeam ONE 13.0.2, the recommended action is to install Patch 1, build 13.0.2.7159. The company has confirmed that these updated builds contain the necessary fixes.

What You Should Do

  • Apply Patches Immediately: Identify all Veeam ONE 13 deployments and verify their current build numbers. Any environment running a version older than 13.1.0.7233 or 13.0.2.7159 should be considered vulnerable until the appropriate update is applied.
  • Review Outbound SMB Activity: Security teams should scrutinize outbound SMB and NTLM authentication traffic originating from Veeam ONE servers. Unexpected SMB connections to untrusted hosts, particularly over TCP port 445, could signal an attempt at authentication coercion.
  • Implement Network Controls: Restrict outbound SMB traffic from Veeam ONE servers using network firewalls and other controls to minimize exposure.
  • Enable SMB Security Features: Utilize SMB signing and Extended Protection for Authentication to help mitigate the risks associated with credential relay attacks.
  • Adhere to Least Privilege: Ensure that the Veeam ONE service account operates with the principle of least privilege. It should not possess unnecessary permissions such as domain administrator, local administrator, backup repository access, or virtualization management privileges.
  • Monitor for Suspicious Activity: Regularly monitor logs for authentication failures, unusual activity from the service account, and any suspicious access attempts to backup systems. This can help detect potential abuse of compromised credentials.

This disclosure underscores the persistent threat posed by authentication coercion vulnerabilities within critical enterprise management platforms. Prompt application of Veeam’s patches and proactive measures to reduce unnecessary NTLM exposure are crucial steps in safeguarding backup infrastructure against credential theft and lateral movement.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEHackerPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Apache Log4j2 Flaw Lets Attackers Bypass Security and Execute Code

Next Post

Ransomware Hacker Uses AI to Plan Cyberattacks Against 20+ Orgs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Stolen SSNs of Corporate Execs Sold for 25 Cents on Dark Web
August 27, 2026
Critical TP-Link Kasa Smart Home Vulnerability Lets Attackers Disrupt Devices
August 27, 2026
CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks
August 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us