the software that's supposed to save you from ransomware just scored a perfect 10

Veeam disclosed six vulnerabilities in Veeam ONE, and the worst one lets a stranger run code on your backup monitoring server with zero credentials…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-64633 (CVSS v4: 10.0) is unauthenticated remote code execution on the Veeam ONE agent host.

The short version

Five more CVEs were disclosed in the same batch: an arbitrary file read, a privileged-access code exec bug, a SQL injection, a local privilege escalation, and an unauthorized report-data access flaw.

The short version

Affected: Veeam ONE 13.0.2.6723 and all earlier version 13 builds.

The short version

Fixed in 13.1.0.7034 — detailed in Veeam's own KB4892.

The short version

Disclosed responsibly through Veeam's HackerOne bug bounty program on July 29, 2026 — no evidence of active exploitation yet, but that historically doesn't last long.

Patch priority

Update Veeam ONE to 13.1.0.7034 this week, full stop — not because there's a confirmed active attack yet, but because backup infrastructure sitting on a maximum-severity unauthenticated RCE is…

Aliteq

Read the full story

the software that's supposed to save you from ransomware just scored a perfect 10

Read the full story on Aliteq