Threat Advisory

Veeam ONE and Backup Flaw Uncover Plaintext OS Entry Records

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Veeam has released security updates addressing two vulnerabilities affecting its enterprise backup and monitoring products. The most critical issue involves an SMB authentication coercion flaw in Veeam ONE that allows an unauthenticated network attacker to force the service account to authenticate to an attacker-controlled system, potentially enabling credential relay attacks. The second issue impacts Veeam Backup & Replication and causes guest OS credentials used for Application Aware Processing to be stored in cleartext logs, allowing attackers with access to those logs to retrieve sensitive credentials. Although no active exploitation has been reported, organizations using affected Veeam products should apply the available patches immediately due to the critical role backup infrastructure plays in enterprise recovery operations.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Veeam has released security updates addressing two vulnerabilities affecting its enterprise backup and monitoring products. The most critical issue involves an SMB authentication coercion flaw in Veeam ONE that allows an unauthenticated network attacker to force the service account to authenticate to an attacker-controlled system, potentially enabling credential relay attacks. The second issue impacts Veeam Backup & Replication and causes guest OS credentials used for Application Aware Processing to be stored in cleartext logs, allowing attackers with access to those logs to retrieve sensitive credentials. Although no active exploitation has been reported, organizations using affected Veeam products should apply the available patches immediately due to the critical role backup infrastructure plays in enterprise recovery operations.[emaillocker id="1283"]

CVE-2026-65641 (CVSS 9.3 — Critical): A vulnerability in Veeam ONE allows an unauthenticated network attacker to force SMB authentication from the service account, potentially enabling NTLM relay attacks and unauthorized access to other systems.

CVE-2026-58070 (CVSS 6.8 — Medium): A vulnerability in Veeam Backup & Replication allows guest OS credentials used during Application Aware Processing to be stored in cleartext within guest machine logs, enabling users with access to those logs to recover sensitive credentials.

 

RECOMMENDATIONS:

  • We recommend you to update Veeam ONE to version 13.1.0.7233 or 13.0.2.7159 or later.
  • We recommend you to move Veeam Backup and Replication to version 13.1.0.411 or 13.0.3.63 or later.

 

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/veeam-cve-2026-65641-smb-vulnerability/

[/emaillocker]
crossmenu