T
Threats
Veeam Critical Vulnerabilities
Overview
Vendor: Veeam
Products: Veeam Service Provider Console and Veeam ONE
CVEs: CVE-2026-64633, CVE-2026-58073
Severity: Critical
Highest CVSS: 10.0
Date: 5 August 2026
Veeam has released security updates for two critical vulnerabilities across Veeam ONE and Veeam Service Provider Console. Both flaws are remotely exploitable without authentication. Successful exploitation could lead to remote code execution on a Veeam ONE agent host or the theft of credentials belonging to a managed Service Provider Console agent.
Affected Versions
Veeam ONE - CVE-2026-64633
Affected: Veeam ONE 13.0.2.6723 and all earlier version 13 builds
Fixed: Veeam ONE 13.1.0.7034
Not affected: Veeam has not published a separate unaffected-version or configuration statement.
Source: Veeam ONE 13.1 security advisory
Veeam Service Provider Console - CVE-2026-58073
Affected: Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds
Fixed: Veeam Service Provider Console 9.3.0.35057
Not affected: Veeam has not published a separate unaffected-version or configuration statement.
Source: Veeam Service Provider Console 9.3 security advisory
Vulnerability Breakdown
CVE-2026-64633 - Unauthenticated Remote Code Execution
Product: Veeam ONE
Severity: Critical
CVSS: 10.0, CVSS v4.0
Published: 29 July 2026
Description: CVE-2026-64633 allows a remote, unauthenticated attacker to execute code on the Veeam ONE agent host.
Impact: Successful exploitation can compromise the confidentiality, integrity and availability of the agent host and connected systems.
Conditions: No authentication or user interaction is required. The affected service must be network reachable.
Action: Upgrade to Veeam ONE 13.1.0.7034.
CVE-2026-58073 - Managed Agent Impersonation and Credential Theft
Product: Veeam Service Provider Console
Severity: Critical
CVSS: 9.5, CVSS v4.0
Published: 4 August 2026
Description: CVE-2026-58073 allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials.
Impact: Successful exploitation can expose managed-agent credentials and compromise access associated with that agent.
Conditions: No authentication or user interaction is required. Veeam rates attack complexity as high.
Action: Upgrade to Veeam Service Provider Console 9.3.0.35057.
Mitigation
Upgrade Veeam ONE to version 13.1.0.7034.
Upgrade Veeam Service Provider Console to version 9.3.0.35057.
Prioritise internet-facing or otherwise untrusted-network-accessible systems.
Review affected hosts and managed-agent accounts for unexpected access or activity.
Veeam has not published a workaround for either vulnerability. Applying the fixed builds is the required remediation.
Summary for IT Teams
Products: Veeam ONE and Veeam Service Provider Console
Threat Level: Critical, CVSS 10.0 and 9.5
Action Required: Upgrade Veeam ONE to 13.1.0.7034 and Veeam Service Provider Console to 9.3.0.35057 immediately. Review exposed systems and associated agent credentials for suspicious activity.
Reference
Need Help?
Secure ISS can assist with exposure assessment, upgrade planning and post-update validation. Contact the Secure ISS SOC team on 1300 769 460.

