T

Threats

Veeam Critical Vulnerabilities

Overview

  • Vendor: Veeam

  • Products: Veeam Service Provider Console and Veeam ONE

  • CVEs: CVE-2026-64633, CVE-2026-58073

  • Severity: Critical

  • Highest CVSS: 10.0

  • Date: 5 August 2026


Veeam has released security updates for two critical vulnerabilities across Veeam ONE and Veeam Service Provider Console. Both flaws are remotely exploitable without authentication. Successful exploitation could lead to remote code execution on a Veeam ONE agent host or the theft of credentials belonging to a managed Service Provider Console agent.


Affected Versions

Veeam ONE - CVE-2026-64633

  • Affected: Veeam ONE 13.0.2.6723 and all earlier version 13 builds

  • Fixed: Veeam ONE 13.1.0.7034

  • Not affected: Veeam has not published a separate unaffected-version or configuration statement.

  • Source: Veeam ONE 13.1 security advisory

Veeam Service Provider Console - CVE-2026-58073

  • Affected: Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds

  • Fixed: Veeam Service Provider Console 9.3.0.35057

  • Not affected: Veeam has not published a separate unaffected-version or configuration statement.

  • Source: Veeam Service Provider Console 9.3 security advisory


Vulnerability Breakdown

CVE-2026-64633 - Unauthenticated Remote Code Execution

  • Product: Veeam ONE

  • Severity: Critical

  • CVSS: 10.0, CVSS v4.0

  • Published: 29 July 2026

  • Description: CVE-2026-64633 allows a remote, unauthenticated attacker to execute code on the Veeam ONE agent host.

  • Impact: Successful exploitation can compromise the confidentiality, integrity and availability of the agent host and connected systems.

  • Conditions: No authentication or user interaction is required. The affected service must be network reachable.

  • Action: Upgrade to Veeam ONE 13.1.0.7034.

CVE-2026-58073 - Managed Agent Impersonation and Credential Theft

  • Product: Veeam Service Provider Console

  • Severity: Critical

  • CVSS: 9.5, CVSS v4.0

  • Published: 4 August 2026

  • Description: CVE-2026-58073 allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials.

  • Impact: Successful exploitation can expose managed-agent credentials and compromise access associated with that agent.

  • Conditions: No authentication or user interaction is required. Veeam rates attack complexity as high.

  • Action: Upgrade to Veeam Service Provider Console 9.3.0.35057.


Mitigation

  • Upgrade Veeam ONE to version 13.1.0.7034.

  • Upgrade Veeam Service Provider Console to version 9.3.0.35057.

  • Prioritise internet-facing or otherwise untrusted-network-accessible systems.

  • Review affected hosts and managed-agent accounts for unexpected access or activity.

  • Veeam has not published a workaround for either vulnerability. Applying the fixed builds is the required remediation.


Summary for IT Teams

  • Products: Veeam ONE and Veeam Service Provider Console

  • Threat Level: Critical, CVSS 10.0 and 9.5

  • Action Required: Upgrade Veeam ONE to 13.1.0.7034 and Veeam Service Provider Console to 9.3.0.35057 immediately. Review exposed systems and associated agent credentials for suspicious activity.


Reference


Need Help?

Secure ISS can assist with exposure assessment, upgrade planning and post-update validation. Contact the Secure ISS SOC team on 1300 769 460.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.