AI description
CVE-2026-65641 is a vulnerability found in Veeam ONE that allows an unauthenticated network attacker to coerce Server Message Block (SMB) authentication from the service account. This flaw enables an attacker to force the server to authenticate to a system they control, potentially leading to relay attacks against other hosts. The vulnerability affects Veeam ONE version 13.1.0.7034 and all earlier version 13 builds. Veeam has released updates, specifically Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159), to address this issue.
- Description
- A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
- Source
- support@hackerone.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- support@hackerone.com
- CWE-288
- Hype score
- Not currently trending
Critical CVE-2026-65641 in Veeam ONE: unauthenticated SMB auth coercion. Affects 13.1.0.7034 and earlier v13 builds (not 12.x). Patch to 13.1.0.7233 or 13.0.2.7159. https://t.co/igsKlIOh5G https://t.co/stqqGJ5Ch4
@getShiftWire
13 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-65641 (CVSS 9.3): Veeam ONEの脆弱性により、認証されていない攻撃者がSMB認証を強制的に実行できる CVE-2026-65641 (CVSS 9.3): Veeam ONE Flaw Lets Unauthenticated Attacker Coerce SMB Authentication #DailyCyberSecurity (Aug 26) https://t.co/
@foxbook
27 Aug 2026
242 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-65641 (CVSS 9.3) affects Veeam ONE. An unauthenticated network attacker can coerce the Veeam ONE service account into performing SMB authentication, potentially exposing NTLM credentials. 🔴 Patch Veeam ONE immediately. Fixed in 13.1.0.7233 and https:
@ThreatWire_
26 Aug 2026
3739 Impressions
10 Retweets
29 Likes
11 Bookmarks
1 Reply
0 Quotes
Veeam patches multiple vulnerabilities in Veeam ONE 13.x and 12.x branches. CVE-2026-65641 (CVSS 9.3) allows service-account SMB authentication while CVE-2026-64633 scores a perfect 10.0. Seven issues are now fixed across 13.1.0.7233, 13.0.2.7159 and 12.3.0.7165 releases.
@WorldCyberNewsX
26 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes