Cybersecurity & Protection

Veeam ONE: Critical Flaw Puts Service Account at Risk

Aug 28, 2026 2 min read
All articles

For security reasons, you should update Veeam ONE promptly. If you don't, attackers can exploit a critical vulnerability to attack instances of the monitoring and reporting solution.

Access to the service account's login hash

According to a security advisory, the now-fixed vulnerability (CVE-2026-65641) is rated critical. It lets unauthenticated attackers over the network trick Veeam ONE servers into connecting to a system they control. In doing so, they gain access to the Net-NTLM login hash of the Veeam ONE service account.

A service account isn't an ordinary user account. Through such an account, a Windows service can, for example, access servers or read information from the IT environment. If the account holds far-reaching privileges, though, attackers can cause considerable damage with it too, for instance by using it to gain access to further systems.

Patch available, no known attacks yet

The developers say they've fixed the security issue in Veeam ONE 13.1 Patch 0 (build 13.1.0.7233) and Veeam ONE 13.0.2 Patch 1 (build 13.0.2.7159). So far, the vendor has no indication that attackers are already exploiting the flaw. If you run Veeam ONE, you should still apply the update promptly, especially since a compromised service account with far-reaching privileges could give attackers a valuable foothold for further attacks in your environment.