CVE-2026-58075Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-04: 2Mentions · 2026-08-06: 1Patch / Workaround · 2026-08-04: 2Technical Details · 2026-08-04: 2Technical Details · 2026-08-06: 108-0408-06
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-042
Patch2
2026-08-061
Disclosure1
Full discourse3 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-64633 (CVSS 10.0) + CVE-2026-58075 (CVSS 8.7): Unauthenticated RCE and arbitrary file read on Veeam ONE agent host 🔗FOFA Link: https://en.fofa.info/result?qbase64=dGl0bGU9IlZlZWFtIE9ORSI%3D 🎯1.1K+ Results are found on http://en.fofa.info in the past year. FOFA Query: title="Veeam ONE" 🔖Refer: https://veeam.com/kb4892 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces two high‑severity CVEs (CVE-2026-64633 and CVE-2026-58075) affecting Veeam ONE, outlining unauthenticated remote code execution and arbitrary file read capabilities.

    0240834416.1K
    14.8K followersView on X
  • yousukezan@yousukezan
    Patch

    Veeam ONEに重大な脆弱性CVE-2026-64633が見つかり、認証不要でリモートから任意コードを実行できることが明らかになった。Veeamはこの脆弱性を含む6件の問題を修正したVeeam ONE 13.1.0.7034を公開しており、バックアップ監視基盤が標的となるリスクから速やかな更新を推奨している。 CVE-2026-64633は、監視対象ホスト上で動作するVeeam ONEエージェントに存在し、ネットワーク経由で認証なしに任意コードを実行できる。ユーザー操作やログインは不要で、到達可能なエージェントが侵害されると攻撃の足掛かりとなる可能性がある。現時点で悪用事例やPoCは公開されていない。 今回の更新では、このほかにも5件の脆弱性が修正された。CVE-2026-58075(CVSS 8.7)は認証不要で任意ファイルを読み取れる問題、CVE-2026-58074およびCVE-2026-64631(ともにCVSS 8.6)は権限を持つ、または低権限ユーザーによるコード実行やSQLインジェクション、CVE-2026-64634(CVSS 8.4)はローカル権限昇格、CVE-2026-64630(CVSS 5.3)は共有レポートデータの情報漏えいに関する問題である。 影響を受けるのはVeeam ONE 13.0.2.6723およびそれ以前のバージョン13系で、回避策は提供されていない。Veeamは13.1.0.7034への更新と、更新完了までの間はVeeam ONEエージェントへのネットワークアクセスを制限するよう案内している。 https://securityonline.info/veeam-one-cve-2026-64633-rce/

    Post summary

    The post announces a discovered CVE‑2026‑64633 allowing unauthenticated remote code execution, provides patch details and recommends updating to Veeam ONE 13.1.0.7034 while limiting agent access.

    000411.4K
    15.0K followersView on X
  • yousukezan@yousukezan
    Patch

    Veeam ONEに重大な脆弱性CVE-2026-64633が見つかり、認証不要でリモートから任意コードを実行できることが明らかになった。Veeamはこの脆弱性を含む6件の問題を修正したVeeam ONE 13.1.0.7034を公開しており、バックアップ監視基盤が標的となるリスクから速やかな更新を推奨している。 CVE-2026-64633は、監視対象ホスト上で動作するVeeam ONEエージェントに存在し、ネットワーク経由で認証なしに任意コードを実行できる。ユーザー操作やログインは不要で、到達可能なエージェントが侵害されると攻撃の足掛かりとなる可能性がある。現時点で悪用事例やPoCは公開されていない。今回の更新では、このほかにも5件の脆弱性が修正された。 CVE-2026-58075(CVSS 8.7)は認証不要で任意ファイルを読み取れる問題、CVE-2026-58074およびCVE-2026-64631(ともにCVSS 8.6)は権限を持つ、または低権限ユーザーによるコード実行やSQLインジェクション、CVE-2026-64634(CVSS 8.4)はローカル権限昇格、CVE-2026-64630(CVSS 5.3)は共有レポートデータの情報漏えいに関する問題である。 影響を受けるのはVeeam ONE 13.0.2.6723およびそれ以前のバージョン13系で、回避策は提供されていない。Veeamは13.1.0.7034への更新と、更新完了までの間はVeeam ONEエージェントへのネットワークアクセスを制限するよう案内している。 https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/

    Post summary

    The post announces the discovery of CVE-2026-64633, a no‑authentication, remote code execution flaw in Veeam ONE, and informs readers of a patch version (13.1.0.7034) and recommends updating and limiting network access to the agent until the patch is applied.

    000111.2K
    14.7K followersView on X

Explore more