Skip to content
VulniPulse

Veeam Veeam ONE Vulnerabilities & Security Advisories

4 advisories tracked · Veeam Knowledge Base — Security Advisories · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Veeam advisory that VulniPulse classified as Veeam ONE, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 2 critical.

Android app · Google Play

Monitor Veeam CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Veeam Knowledge Base — Security Advisories

Polled via the official Veeam Support KB Atom feed, filtered to security advisories (KB articles mentioning CVEs or vulnerabilities). KB pages are fetched for new items to extract build numbers and fixes.

Latest Veeam Veeam ONE advisories

Critical9.3Veeam

Critical [CVE-2026-65641] Vulnerability Resolved in Veeam ONE 13.1 Patch 0

Vulnerability Resolved in Veeam ONE 13.1 Patch 0 KB ID: 4905 Product: Published: 2026-08-25 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. Severity: Critical CVSS v4.0 Score: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L

CVE-2026-65641
Veeam ONE
Aug 25, 2026
UnratedVeeam

Advisory [CVE-2026-58074 +2] Release Information for Veeam ONE 12 and Updates

Release Information for Veeam ONE 12 and Updates KB ID: 4705 Product: Published: 2024-12-23 Last Modified: 2026-08-25 Veeam ONE v12 Releases 12.3.0.7165 What's New Veeam ONE 12.3 Patch 1 is a cumulative maintenance and security update for Veeam ONE 12.3. It resolves reported issues across reporting, monitoring, alarms, licensing, and integrations, adds REST API and ServiceNow enhancements, and addresses externally reported security vulnerabilities. Applying this patch is recommended for all Veeam ONE 12.3 deployments. New Features and Improvements Cloud Backup Sizes in the REST API The public REST API now reports the size of cloud backups and of their restore points. AWS Account Identification Veeam ONE now collects the AWS Account ID and account alias for workloads protected by Veeam Backup for AWS, and the public REST API returns both for protected Amazon EC2 workloads. Customizable ServiceNow Short Description Resolved Issues - Veeam ONE repeatedly logs an error because triggered alarms are not synchronized correctly between the alarm cache and the database: Cannot insert the value NULL into column 'triggered_alarm_id' - The Backup Copy RPO alarm reports incorrect information because deleted backup copy workers are still taken into account. - The Backup Job State alarm does not raise a Warning when a backup job session finishes with a warning.

CVE-2026-58074CVE-2026-64631CVE-2026-64632
Veeam ONE
Aug 25, 2026
UnratedVeeam

Advisory [CVE-2026-58074 +7] List of Security Fixes and Improvements in Veeam ONE

List of Security Fixes and Improvements in Veeam ONE KB ID: 4858 Product: Published: 2026-05-27 Last Modified: Purpose This article aims to provide our customers' security and compliance teams with detailed information on security improvements between releases to help them make an informed decision on whether it is critical to upgrade from their current Veeam ONE version to a later one. 13.1.0.7233 13.1.0.7034 - AutoMapper was replaced with MagicMapper 14.0.1. - Azure. Identity upgraded to version 1.17.2 - @babel/runtime upgraded to version 7.29.2 - dompurify upgraded to version 3.4.11 - ip-address upgraded to version 10.1.1 - Microsoft. IdentityModel. JsonWebTokens upgraded to version 8.17.0 - System. IdentityModel. Tokens. Jwt upgraded to version 8.17.0 - System. Private. Uri upgraded to version 4.3.2 - System. Security. Cryptography. Xml upgraded to version 10.0.7 - vite upgraded to version 8.0.16 13.0.2.7159 - d3-color upgraded to version 3.1.0 - OpenSSL upgraded to version 3.0.21 - SQLite (SQLitePCLRaw e_sqlite3) upgraded to version 3.0.3 13.0.2.6723 - postcss upgraded to version 8.5.13 - uuid upgraded to version 14.0.0 12.3.0.7165 Related Articles If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.

CVE-2026-58074CVE-2026-58075CVE-2026-64630+5
Veeam ONE
Aug 4, 2026
Critical10.0Veeam

Critical [CVE-2026-58074 +6] Vulnerabilities Resolved in Veeam ONE 13.1

Vulnerabilities Resolved in Veeam ONE 13.1 KB ID: 4892 Product: Published: 2026-08-04 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability allowing remote unauthenticated code execution on the agent host. Severity: Critical CVSS v4.0 Score: 10.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVE-2026-58074CVE-2026-58075CVE-2026-64630+4
Veeam ONE
Jul 29, 2026

← All Veeam advisories