SMB Authentication Coercion Vulnerability in Veeam Software
CVE-2026-65641

9.3CRITICAL

Key Information:

Vendor

Veeam

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-65641?

CVE-2026-65641 is a vulnerability found in Veeam Software, specifically affecting its SMB (Server Message Block) authentication process. This vulnerability enables an unauthenticated network attacker to coerce the service account to perform SMB authentication. Veeam Software plays a crucial role in data backup and recovery, making it an integral part of many organizations' IT infrastructure. The exploitation of this vulnerability could negatively impact an organization by compromising the security of sensitive data and potentially allowing unauthorized access to critical systems. The nature of the vulnerability raises concerns about the integrity and confidentiality of data handled by Veeam's products, making it essential for organizations to take proactive measures to safeguard their systems.

Potential impact of CVE-2026-65641

  1. Unauthorized Access: The vulnerability allows unauthenticated attackers to coerce SMB authentication, potentially granting them unauthorized access to sensitive systems and data within the organization.

  2. Data Breaches: If exploited, CVE-2026-65641 could lead to significant data breaches, exposing customer information, proprietary data, and other sensitive materials, thereby increasing the risk of compliance violations and reputational damage.

  3. Service Disruption: Attacks leveraging this vulnerability could lead to the disruption of Veeam's backup and recovery services, impacting an organization's ability to restore critical systems and data in the event of an incident or outage, which could result in operational downtime and financial loss.

Affected Version(s)

One 0 < 13.1

One 0 < 13.0.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.