| Severity | CRITICAL |
| Threat Category | Vulnerability (Remote Unauthenticated Code Execution) |
| Affected Platforms | Veeam ONE (versions 13.0.2.6723 and earlier Version 13 builds) |
| CVE | NVD – CVE-2026-64633 |
| CVSS | 10.0 (CVSSv4.0) |
1. Overview
BtCIRT is issuing this advisory to inform government agencies, businesses, and the public in Bhutan about a critical vulnerability affecting Veeam ONE, a monitoring and capacity-planning software for backup and virtual environments. Veeam Knowledge Base article KB4892 (published 2026-08-04, updated 2026-08-05) discloses six vulnerabilities in Veeam ONE 13. The most severe, CVE-2026-64633, is a remote unauthenticated code execution flaw in the Veeam ONE agent host, rated 10.0 (Critical) on CVSSv4.0 — no authentication is required, and successful exploitation can grant an attacker full control of the affected system. This is corroborated by the NVD record cited above and by Cyber Security News (“Multiple Veeam ONE Vulnerabilities Let Attackers Execute Remote Code,” published 2026-08-05), which reports the flaw enables remote code execution without credentials and warns it could lead to malware deployment, lateral movement, credential theft, and ransomware activity.
2. Who is Affected
At the time of publication, BtCIRT has not received confirmed reports of this vulnerability being exploited in Bhutan. The risk is nonetheless assessed as Critical: the flaw requires no authentication, is remotely exploitable, and affects any organization running vulnerable versions of Veeam ONE, particularly where systems are exposed to untrusted networks.
3. How the Vulnerability Works
- Root cause: Veeam ONE 13’s agent component allows an unauthenticated remote actor to trigger code execution on the agent host, without valid credentials or user interaction. Exploitation (CVE-2026-64633): An attacker with network access to a vulnerable agent host sends crafted requests to the exposed service, achieving arbitrary code execution.
- Potential chaining with related flaws: Related vulnerabilities disclosed in the same KB4892 advisory could be combined with CVE-2026-64633 to deepen an intrusion.
- Impact: Successful exploitation grants code execution with no prior access, enabling lateral movement, credential theft, further malware, or ransomware — especially damaging given Veeam ONE’s role in monitoring backup infrastructure.
4. Indicators to Watch For
● Veeam ONE agent hosts running version 13.0.2.6723 or earlier (verify build against 13.1.0.7034).
● Unexpected processes on the agent host, or unusual inbound connections to the Veeam ONE agent service from unfamiliar or external IP addresses.
● Agent or service logs showing malformed, unusual, or repeated requests preceding a crash or restart.
● Unexplained access to configuration files, credential stores, logs, or anomalous database activity on hosts running the Veeam ONE agent.
● New or modified local accounts, or privilege changes, on hosts running the Veeam ONE Reporter service.
5. Recommendations
For organizations and government offices:
● Identify all Veeam ONE 13 deployments and confirm build versions immediately.
● Upgrade all affected instances to version 13.1.0.7034 without delay, prioritizing agent hosts reachable from untrusted networks.
● Where immediate patching isn’t possible, restrict network access to trusted, segmented networks (firewall rules or VPN) and disable unnecessary external exposure.
● Review logs for the indicators in Section 4 since the disclosure date (2026-08-04), and apply least privilege to Veeam ONE service accounts and Reporter service contexts to limit the impact of related privilege-escalation flaws (CVE-2026-58074, CVE-2026-64634).
● Include backup infrastructure monitoring tools such as Veeam ONE in regular vulnerability management and patch cycles, given their value as ransomware targets.
6. Reporting
If you suspect your organization, device or account has been affected by this threat, or observe activity matching this pattern, please report it to BtCIRT at cirt@btcirt.bt
7. Sources and References
- Veeam, “Vulnerabilities Resolved in Veeam ONE 13.1” (KB4892), published 2026-08-04, last modified 2026-08-05:
https://www.veeam.com/kb4892 - Cyber Security News, “Multiple Veeam ONE Vulnerabilities Let Attackers Execute Remote Code”, published 2026-08-05:
https://cybersecuritynews.com/multiple-veeam-one-vulnerabilities/
