CVE-2026-65641Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-08-26); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-08-26: 5Mentions · 2026-08-27: 2Mentions · 2026-09-04: 1Patch / Workaround · 2026-08-26: 4Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-04: 1Technical Details · 2026-08-26: 4Technical Details · 2026-08-27: 2Technical Details · 2026-09-04: 108-2608-2709-04
Signal classification3 categories
Patch
675.0%
General
112.5%
Disclosure
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-265
General1Patch4
2026-08-272
Disclosure1Patch1
2026-09-041
Patch1
Full discourse8 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-65641 (CVSS 9.3) affects Veeam ONE. An unauthenticated network attacker can coerce the Veeam ONE service account into performing SMB authentication, potentially exposing NTLM credentials. 🔴 Patch Veeam ONE immediately. Fixed in 13.1.0.7233 and 13.0.2.7159. 🔗 https://www.veeam.com/kb4905 #Veeam #VeeamONE #CVE #SMB #NTLM #CyberSecurity #Infosec

    Post summary

    A critical CVE (CVE-2026-65641) for Veeam ONE is highlighted, detailing the vulnerability and urging users to apply the specific patches released in versions 13.1.0.7233 and 13.0.2.7159.

    11003494.8K
    1.7K followersView on X
  • Günter Born@etguenni
    General

    Veeam ONE with Critical Vulnerability CVE-2026-65641 (CVSS 9.3) https://borncity.com/win/2026/08/27/veeam-one-with-critical-vulnerability-cve-2026-65641-cvss-9-3/

    Post summary

    The article flags the existence of a critical vulnerability (CVE‑2026‑65641) with high CVSS 9.3 but offers no further technical details, exploit information, or patch guidance.

    05030740
    2.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A critical Veeam ONE vulnerability (CVE-2026-65641, CVSS 9.3) lets an unauthenticated attacker coerce SMB authentication. Patch Veeam now. #Veeam #CyberSecurity #CVE202665641 #SMB #Infosec https://securityonline.info/veeam-cve-2026-65641-smb-vulnerability/

    Post summary

    The post announces a critical SMB authentication flaw in Veeam ONE (CVE-2026-65641) with a CVSS of 9.3, urging users to apply the vendor patch.

    01051559
    13.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical authentication bypass in #VeeamONE! CVE-2026-65641 CVSS: 9.3. Unauthenticated remote attackers can coerce SMB authentication from the #Veeam ONE service account. https://ccb.belgium.be/advisories/warning-critical-veeam-one-authentication-bypass-vulnerability-patch-immediately #Patch #Patch #Patch

    Post summary

    CVE‑2026‑65641 is a critical authentication bypass in Veeam ONE (CVSS 9.3) that forces SMB authentication via the Veeam ONE service account; users are strongly advised to apply the patch immediately.

    02001343
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 『A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.』 CVE-2026-65641 Severity: Critical KB4905: Vulnerability Resolved in Veeam ONE 13.1 Patch 0 https://www.veeam.com/kb4905

    Post summary

    The tweet announces a critical SMB authentication exploitation flaw (CVE-2026-65641), confirms it was mitigated by Veeam ONE 13.1 Patch 0, and directs readers to the vendor’s support page.

    00011398
    7.0K followersView on X
  • Günter Born@etguenni
    Patch

    Kritische Veeam ONE-Schwachstelle CVE-2026-65641 (CVSS 9.3) - patchen https://borncity.com/blog/2026/08/27/veeam-one/

    Post summary

    The post urges users to patch Veeam ONE for the critical CVE‑2026‑65641 vulnerability (CVSS 9.3), with no mention of PoC, exploit code, or active attacks.

    01000248
    2.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Veeam ONE の深刻な脆弱性 CVE-2026-65641 が FIX:SMB 認証強制の可能性 https://iototsecnews.jp/2026/08/27/critical-veeam-one-flaw-lets-unauthenticated-attackers-coerce-smb-authentication-from-service-accounts/ 監視や管理を担うツールである Veeam ONE のバージョン 13 系において、認証不要で悪用できる深刻な脆弱性 CVE-2026-65641 が確認されました。この問題により、ネットワーク上の攻撃者からサービスアカウントの Net-NTLM 認証情報を外部へ強制送信させられ、オフライン解析/リレー攻撃による権限昇格/バックアップ基盤への不正アクセスといった被害につながる恐れがあります。対応策として、最新のパッチ適用による修正済みビルドへの更新/サービスアカウントの権限最小化/不要な SMB 通信の制限/異常な NTLM 認証の監視が求められます。 #CVE202665641 #VeeamONE #Vulnerability

    Post summary

    A critical authentication bypass flaw (CVE-2026-65641) in Veeam ONE V13 allows attackers to coerce NTLM credentials, with vendor patches and mitigation steps now available.

    0000083
    513 followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-65641 (CVSS 9.3): Veeam ONEの脆弱性により、認証されていない攻撃者がSMB認証を強制的に実行できる CVE-2026-65641 (CVSS 9.3): Veeam ONE Flaw Lets Unauthenticated Attacker Coerce SMB Authentication #DailyCyberSecurity (Aug 26) https://securityonline.info/veeam-cve-2026-65641-smb-vulnerability/

    Post summary

    CVE‑2026‑65641 reveals a high‑severity flaw in Veeam ONE that allows unauthenticated attackers to forcibly trigger SMB authentication, but the text gives only basic disclosure details without PoC, exploit, or patch information.

    00000263
    4.9K followersView on X

Explore more