Cyber Security News

Multiple Veeam ONE Vulnerabilities Allow Code Execution Attacks

Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files, steal database data, and escalate privileges.

The most severe issue, tracked as CVE-2026-64633, has received a critical CVSS v4.0 score of 10.0 because it allows remote, unauthenticated code execution on the Veeam ONE agent host.

The vulnerabilities affects Veeam ONE 13.0.2.6723 and all earlier version 13 builds. Organizations using affected deployments should update immediately to Veeam ONE 13.1.0.7034, the version that resolves all issues listed in Veeam Knowledge Base article KB4892.

CVE-2026-64633 is the most dangerous flaw in the advisory. It could allow a remote attacker to execute arbitrary code on an exposed agent host without authentication.

A successful exploit could give threat actors a foothold in the targeted environment, potentially enabling malware deployment, lateral movement, credential theft, or ransomware activity.

Multiple Veeam ONE Vulnerabilities

Another high-severity issue, CVE-2026-58075, enables an unauthenticated attacker to read arbitrary files from the host. Attackers could use this capability to access configuration files, credentials, logs, or other sensitive data. Veeam noted that this issue could also be leveraged to support local privilege escalation.

CVE-2026-58074 affects high-privileged users and allows arbitrary code execution on the Veeam ONE server. While exploitation requires elevated access, the vulnerability could allow an insider or attacker who has already compromised a privileged account to run malicious code and expand their control over the server.

The Veeam advisory (KB4892) also addresses CVE-2026-64631, an SQL injection vulnerability that allows low-privileged users to extract database contents.

The flaw could expose infrastructure details, backup information, account data, and operational records, helping attackers map the environment and identify high-value systems.

CVE-2026-64634 allows local privilege escalation to the Reporter service context. An attacker with local access could exploit the flaw to gain additional permissions and access to functions or data available to that service.

CVE IDIssueSeverity
CVE-2026-64633Unauthenticated RCECritical
CVE-2026-58075Arbitrary file readHigh
CVE-2026-58074Privileged code executionHigh
CVE-2026-64631SQL injectionHigh
CVE-2026-64634Local privilege escalationHigh
CVE-2026-64630Unauthorized report accessMedium

Veeam also fixed CVE-2026-64630, a medium-severity vulnerability that allows low-privileged users to retrieve report data outside the intended scope of a shared report link.

Several vulnerabilities were reported through HackerOne, while CVE-2026-58074 was discovered during Veeam’s internal testing. Veeam stated that attackers often reverse-engineer patches after public disclosures to identify and target unpatched installations.

Security teams should identify all Veeam ONE version 13 deployments, confirm whether they are running builds earlier than 13.1.0.7034, and apply the available update as soon as possible.

Organizations should also review Veeam ONE server and agent exposure, restrict access to trusted administrators, monitor for suspicious activity, and investigate unusual database queries, report access, or code execution events.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago