AI description
CVE-2026-64633 is a vulnerability identified in Veeam ONE that permits remote unauthenticated code execution on the agent host. This flaw allows an attacker to run arbitrary code on the affected system without needing authentication or user interaction. The vulnerability impacts Veeam ONE version 13.0.2.6723 and all prior builds of version 13. Veeam has released an update, version 13.1.0.7034, to address this and other related issues. The vulnerability was reported through HackerOne.
- Description
- A vulnerability allowing remote unauthenticated code execution on the agent host.
- Source
- support@hackerone.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 10
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- support@hackerone.com
- CWE-94
- Hype score
- Not currently trending
⚠️⚠️ CVE-2026-64633 (CVSS 10.0) + CVE-2026-58075 (CVSS 8.7): Unauthenticated RCE and arbitrary file read on Veeam ONE agent host 🔗FOFA Link: https://t.co/AMypDZDjwq 🎯1.1K+ Results are found on https://t.co/NBEEGu7ePJ in the past year. FOFA Query: title="Veeam ONE"
@fofabot
6 Aug 2026
6522 Impressions
19 Retweets
51 Likes
26 Bookmarks
0 Replies
0 Quotes
🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-64633 CVE-2017-20241 CVE-2017-20242 CVE-2025-29296 CVE-2026-0163 ..🧵👇
@exploitgrid
5 Aug 2026
54 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Veeam ONE 13.1 patches six vulnerabilities, including CVE-2026-64633 allowing unauthenticated remote code execution on the agent host (CVSS 10.0 Critical). CVE-2026-58075 permits arbitrary file reads leading to local privilege escalation (CVSS 8.7). Both issues affect the backup
@WorldCyberNewsX
5 Aug 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes