<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Veeam Backup &amp; Replication (13.x) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/veeam-backup--replication-13.x/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 13:58:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/veeam-backup--replication-13.x/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Critical Vulnerabilities in Veeam Backup and ONE Products</title><link>https://feed.craftedsignal.io/briefs/2026-08-veeam-vulnerabilities/</link><pubDate>Wed, 26 Aug 2026 13:58:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-veeam-vulnerabilities/</guid><description>Multiple vulnerabilities, including CVE-2026-58070 and CVE-2026-65641, affect Veeam Backup &amp; Replication and Veeam ONE, potentially allowing unauthorized access to sensitive backup data and security policy bypass.</description><content:encoded><![CDATA[<p>On August 25, 2026, Veeam released security updates to address multiple vulnerabilities affecting Veeam Backup &amp; Replication and Veeam ONE. The vulnerabilities identified as CVE-2026-58070 and CVE-2026-65641 impact Veeam Backup &amp; Replication versions 13.x prior to 13.0.3 and Veeam ONE versions 13.x prior to 13.0.2 Patch 1. These security flaws present a significant risk as they could allow an unauthorized attacker to circumvent established security policies and compromise the confidentiality of sensitive enterprise backup data. Given the central role these products play in disaster recovery and data storage, immediate patching of all internet-facing or reachable instances is critical to prevent exploitation of the management interfaces.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to unauthorized access to backups, potentially resulting in the exfiltration of sensitive organizational data or the destruction of backup sets, which would hinder recovery efforts during a ransomware event. Organizations utilizing these Veeam products must prioritize the application of the vendor-provided patches listed in KB4902 and KB4905.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update Veeam Backup &amp; Replication to version 13.0.3 and Veeam ONE to version 13.0.2 Patch 1 as documented in vendor KBs 4902 and 4905.</li>
<li>Review access logs for the Veeam management console to identify unauthorized access attempts or unusual API calls, particularly from non-standard IP ranges.</li>
<li>Isolate Veeam management interfaces from public network exposure.</li>
<li>Monitor for service-specific errors or unexpected process behavior on the servers hosting Veeam infrastructure components.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>