DIRAS TAKE
Urgent: public exploit code is available, so prioritize mitigation immediately; use network restrictions and isolate Veeam ONE agent hosts while waiting for vendor fixes.
What is CVE-2026-64633?
An unauthenticated remote attacker can execute arbitrary code on Veeam ONE agent hosts; this is tracked as CVE-2026-64633. The flaw affects Veeam ONE branch 13.x (13.0.2 and earlier). An attacker needs network access to the vulnerable service but does not require credentials or user interaction to exploit the vulnerability.
Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Which versions of Veeam ONE are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 13.x | 13.0.2 and earlier |
Is CVE-2026-64633 being exploited?
Public exploit code is available.
How to fix CVE-2026-64633
- Restrict network exposure to Veeam ONE management and agent ports to trusted networks and VPNs.
- Isolate or segment hosts running the Veeam ONE agent from general network access.
- Monitor Veeam ONE and agent logs for unusual activity and suspicious processes on agent hosts.
- Follow Veeam’s official guidance and apply vendor updates or mitigations as soon as they are released.
Frequently asked questions
Is CVE-2026-64633 being actively exploited?
Public exploit code is available for CVE-2026-64633.
Which Veeam ONE versions are affected by CVE-2026-64633?
Veeam ONE branch 13.x is affected; specifically versions 13.0.2 and earlier are listed as vulnerable.
Is there a patch for CVE-2026-64633?
There is no fixed version listed for CVE-2026-64633 in the provided facts; apply vendor guidance and mitigations until a vendor patch is released.
Does CVE-2026-64633 require authentication?
No; CVE-2026-64633 allows unauthenticated remote code execution against the Veeam ONE agent host and does not require credentials or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-64633
- cve.org/CVERecord?id=CVE-2026-64633
- veeam.com/kb4892
- All Veeam CVEs on CVE Radar
- CVEs published in September 2026