ALITEQ.

the software that's supposed to save you from ransomware just scored a perfect 10

Veeam disclosed six vulnerabilities in Veeam ONE, and the worst one lets a stranger run code on your backup monitoring server with zero credentials — exactly the kind of hole ransomware crews go looking for first.

Priya NairUpdated 1h ago7 min readWeb story
Data center backup infrastructure racks, representing the Veeam ONE monitoring platform affected by CVE-2026-64633

Veeam ONE just picked up a 10.0 out of 10 on the CVSS v4 scale — the maximum possible score — for a bug that lets a remote, unauthenticated attacker run arbitrary code on the agent host. No password, no user click, no prior access required. It shipped alongside five other vulnerabilities in the same disclosure, and the fix is version 13.1.0.7034.

Six bugs, one release note

What Veeam patched in 13.1.0.7034

CVE-2026-64633

CVE
Critical (10.0)
Severity
Unauthenticated remote code execution on the agent host

CVE-2026-58075

CVE
High
Severity
Arbitrary file read from host systems

CVE-2026-58074

CVE
High
Severity
Code execution, requires high-privileged server access

CVE-2026-64631

CVE
High
Severity
SQL injection enabling database extraction

CVE-2026-64634

CVE
Medium
Severity
Local privilege escalation to the Reporter service

CVE-2026-64630

CVE
Medium
Severity
Unauthorized access to report data

Why this specific box matters more than the score suggests

Veeam ONE monitors and reports across backup and virtualization environments — it's the dashboard, not the backup engine itself, but it sits right next to the thing your recovery plan depends on. Ransomware crews specifically go after backup infrastructure early in an intrusion, because destroying or encrypting backups is what removes a victim's ability to refuse paying. This year alone we've covered a ransomware crew claiming 657,000 stolen Allstate records and Coca-Cola's Fairlife breach under a two-hour ransom deadline — in both cases, attackers moved fast once they had a foothold, and backup capability is exactly what determines whether a company can walk away from that clock.

Are you affected, and what to do

1

Check your Veeam ONE build — anything at or below 13.0.2.6723 is affected.

2

Update to 13.1.0.7034 following Veeam's KB4892.

3

If the ONE agent host is internet-reachable at all, pull it behind a VPN or firewall regardless of patch status — it shouldn't be exposed either way.

4

Audit for the five other disclosed bugs too; the file-read and SQL injection flaws are meaningful on their own even without the critical RCE.

This isn't Veeam's first RCE disclosure of 2026 either — Veeam Backup & Replication had its own remote code execution flaw reported back in June, letting authenticated domain users run code remotely. Different product, different bug, but the same category of software keeps turning up on patch-now lists, which says something about how much scrutiny backup vendors' attack surface is getting right now — deservedly.

Backup server hardware in a rack, representing the infrastructure Veeam ONE monitors and the target of CVE-2026-64633
Backup and recovery infrastructure is a favorite ransomware target precisely because destroying it removes a victim's ability to refuse paying. · Unsplash

Because this was reported through Veeam's own HackerOne vulnerability disclosure program rather than found already in use, there's no confirmed active exploitation as I'm writing this. That's the good version of how a critical bug gets found. It's also, historically, a countdown — SonicWall's SMA 1000 flaw and N-able's N-central bypass both went from "patch available" to "actively exploited" within days once technical write-ups made the rounds.

Quick answers

Is CVE-2026-64633 being exploited in the wild?
Not as of this writing. It was found through responsible disclosure, not caught in an active attack — but publicly documented critical RCEs in security-adjacent software routinely get weaponized within days to weeks.
What exactly is Veeam ONE, versus Veeam Backup & Replication?
Veeam ONE is the monitoring and reporting layer that sits alongside Veeam's backup products, tracking job health, capacity, and compliance across your backup and virtualization environment. It's a separate install from Backup & Replication itself, but usually deployed right next to it.
Do I need the agent host exposed to the internet for this to matter?
Direct internet exposure is the highest-risk scenario, but anyone who can reach that host on your internal network — including a foothold gained elsewhere in a breach — can potentially exploit it too.
Are the other five CVEs urgent too?
Less individually dramatic than the 10.0 RCE, but the SQL injection and arbitrary file read bugs both hand an attacker real leverage on their own. Patch all six at once — they're fixed in the same 13.1.0.7034 release.
9/ 10

Verdict

Patch priority

Update Veeam ONE to 13.1.0.7034 this week, full stop — not because there's a confirmed active attack yet, but because backup infrastructure sitting on a maximum-severity unauthenticated RCE is exactly the setup that turns a routine breach into a ransomware payday.

Best for: Any organization running Veeam ONE 13.0.2.6723 or earlier

The uncomfortable pattern across this week's disclosures — Veeam, Gitea, Tomcat, N-able before them — is that the infrastructure meant to keep the lights on during an incident is where a lot of the critical bugs are actually landing. Patch the boring, unglamorous monitoring tool before it becomes the reason the fun tool doesn't matter anymore.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading