• PoC PUBLIC

CVE-2026-64633: pre-auth remote code execution in Veeam ONE

An unauthenticated remote attacker can execute arbitrary code on Veeam ONE agent hosts; this is tracked as CVE-2026-64633. The flaw affects Veeam ONE branch 13.x (13.0.2 and earlier). An attacker needs network access to the vulnerable service but does not require credentials or user interaction to exploit the vulnerability.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 4.0
10CRITICAL
EPSS
0.00604
CWE
CWE-94
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code is available, so prioritize mitigation immediately; use network restrictions and isolate Veeam ONE agent hosts while waiting for vendor fixes.

What is CVE-2026-64633?

An unauthenticated remote attacker can execute arbitrary code on Veeam ONE agent hosts; this is tracked as CVE-2026-64633. The flaw affects Veeam ONE branch 13.x (13.0.2 and earlier). An attacker needs network access to the vulnerable service but does not require credentials or user interaction to exploit the vulnerability.

Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Which versions of Veeam ONE are affected?

BRANCHAFFECTEDFIXED
13.x13.0.2 and earlier

Is CVE-2026-64633 being exploited?

Public exploit code is available.

How to fix CVE-2026-64633

  1. Restrict network exposure to Veeam ONE management and agent ports to trusted networks and VPNs.
  2. Isolate or segment hosts running the Veeam ONE agent from general network access.
  3. Monitor Veeam ONE and agent logs for unusual activity and suspicious processes on agent hosts.
  4. Follow Veeam’s official guidance and apply vendor updates or mitigations as soon as they are released.

Frequently asked questions

Is CVE-2026-64633 being actively exploited?

Public exploit code is available for CVE-2026-64633.

Which Veeam ONE versions are affected by CVE-2026-64633?

Veeam ONE branch 13.x is affected; specifically versions 13.0.2 and earlier are listed as vulnerable.

Is there a patch for CVE-2026-64633?

There is no fixed version listed for CVE-2026-64633 in the provided facts; apply vendor guidance and mitigations until a vendor patch is released.

Does CVE-2026-64633 require authentication?

No; CVE-2026-64633 allows unauthenticated remote code execution against the Veeam ONE agent host and does not require credentials or user interaction.

References