{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/veeam-one-13.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Veeam Backup \u0026 Replication (13.x)","Veeam ONE (13.x)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Veeam"],"content_html":"\u003cp\u003eOn August 25, 2026, Veeam released security updates to address multiple vulnerabilities affecting Veeam Backup \u0026amp; Replication and Veeam ONE. The vulnerabilities identified as CVE-2026-58070 and CVE-2026-65641 impact Veeam Backup \u0026amp; Replication versions 13.x prior to 13.0.3 and Veeam ONE versions 13.x prior to 13.0.2 Patch 1. These security flaws present a significant risk as they could allow an unauthorized attacker to circumvent established security policies and compromise the confidentiality of sensitive enterprise backup data. Given the central role these products play in disaster recovery and data storage, immediate patching of all internet-facing or reachable instances is critical to prevent exploitation of the management interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to unauthorized access to backups, potentially resulting in the exfiltration of sensitive organizational data or the destruction of backup sets, which would hinder recovery efforts during a ransomware event. Organizations utilizing these Veeam products must prioritize the application of the vendor-provided patches listed in KB4902 and KB4905.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update Veeam Backup \u0026amp; Replication to version 13.0.3 and Veeam ONE to version 13.0.2 Patch 1 as documented in vendor KBs 4902 and 4905.\u003c/li\u003e\n\u003cli\u003eReview access logs for the Veeam management console to identify unauthorized access attempts or unusual API calls, particularly from non-standard IP ranges.\u003c/li\u003e\n\u003cli\u003eIsolate Veeam management interfaces from public network exposure.\u003c/li\u003e\n\u003cli\u003eMonitor for service-specific errors or unexpected process behavior on the servers hosting Veeam infrastructure components.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T13:58:31Z","date_published":"2026-08-26T13:58:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-veeam-vulnerabilities/","summary":"Multiple vulnerabilities, including CVE-2026-58070 and CVE-2026-65641, affect Veeam Backup \u0026 Replication and Veeam ONE, potentially allowing unauthorized access to sensitive backup data and security policy bypass.","title":"Multiple Critical Vulnerabilities in Veeam Backup and ONE Products","url":"https://feed.craftedsignal.io/briefs/2026-08-veeam-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Veeam ONE (13.x)","version":"https://jsonfeed.org/version/1.1"}