CVE-2026-64633

Veeam · ONE

A critical code injection vulnerability in Veeam ONE allows remote unauthenticated attackers to execute arbitrary code on the agent host.

Executive summary

This critical vulnerability in Veeam ONE poses a severe risk of full system compromise via remote unauthenticated code execution.

Vulnerability

The software contains a code injection flaw (CWE-94) that permits an unauthenticated remote attacker to execute arbitrary code on the underlying agent host. The attack vector is network based and requires no user interaction or prior authentication.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected Veeam ONE agent host. Given the CVSS score of 10.0, this represents the highest level of risk: it can lead to total data exfiltration, complete system compromise, and significant operational downtime.

Remediation

Immediate Action: Update Veeam ONE to the latest available version as specified in the official vendor security advisory (KB4892).

Proactive Monitoring: Monitor network traffic for anomalous patterns originating from the Veeam ONE environment and review system logs for unauthorized process execution.

Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the Veeam ONE agent host to authorized management IPs only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention. Organizations should prioritize updating their Veeam ONE deployments to the latest version to eliminate the code injection path and prevent potential unauthorized access or system takeover.