Executive brief
Veeam ONE is a monitoring and management tool used by enterprises to manage virtualized infrastructure. A critical vulnerability allows unauthenticated attackers to execute arbitrary code on Veeam agent hosts remotely, potentially giving attackers complete control over backup and monitoring systems and the ability to access sensitive data across the entire infrastructure.
Technical details
CVE-2026-64633 is a remote code execution vulnerability in Veeam ONE that allows unauthenticated network access to execute arbitrary code on the agent host. The vulnerability affects Veeam ONE 13.0.2.6723 and all earlier version 13 builds; version 12.x is not affected. The attack requires no authentication, no user interaction, and has a low attack complexity. Patches are available in Veeam ONE 13.1 (build 13.1.0.7034) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159).
Affected products
- Veeam ONE 13.0.2.6723 and earlier 13.x builds
Timeline
- 2026-08-04: disclosed
- 2026-08-04: patched: Patches available in Veeam ONE 13.1.0.7034 and 13.0.2 Patch 1 (build 13.0.2.7159)