NCSC-2026-0283 [1.00] [M/H] Vulnerabilities in Veeam ONE
The vulnerabilities concern multiple software components of Veeam ONE, including agents and services that run with elevated privileges, as well as systems that share reports via shared links and use backend databases. The vulnerabilities make it possible for users with different privilege levels or even unauthorized attackers to perform actions that are normally not permitted. This includes executing arbitrary code on servers or agent hosts, reading arbitrary files without authentication, circumventing access controls on shared report links, executing SQL injection attacks on backend databases, and locally escalating privileges within specific service contexts such as the Reporter service. Exploitation can lead to unauthorized access to sensitive data, system manipulation, and complete compromise of affected systems. Some vulnerabilities require local access, while others can be exploited remotely and without authentication.
CSIRTS triage
- What
- Multiple vulnerabilities enable arbitrary code execution, unauthorized file access, authentication bypass, privilege escalation, and SQL injection across Veeam ONE components.
- Who is affected
- Users of Veeam ONE with any privilege level, including agents and services running with elevated privileges, as well as systems with shared report links.
- Urgency
- High urgency; vulnerabilities allow unauthorized code execution and privilege escalation that can completely compromise affected systems.
- Action
- Apply patches for Veeam ONE as released by Veeam addressing CVE-2026-58074, CVE-2026-58075, CVE-2026-64630, CVE-2026-64631, CVE-2026-64633, and CVE-2026-64634.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Veeam ONE
Get an email when a new Veeam ONE advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0283
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-580740.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580750.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-646300.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-646310.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-646330.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-646340.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-58074 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58075 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64630 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64631 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64633 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64634 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Veeam ONE: Multiple Vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Veeam products (August 5, 2026)cert-fr-avis
- unknownCVE-2026-64634: A vulnerability allowing local privilege escalation to the Reporter service context.nvd
- unknownCVE-2026-64633: A vulnerability allowing remote unauthenticated code execution on the agent host.nvd
- unknownCVE-2026-64631: A vulnerability allowing a low-privileged user to inject SQL and extract database contents.nvd
- unknownCVE-2026-64630: A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a …nvd
- unknownCVE-2026-58075: A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, wh…nvd
- unknownCVE-2026-58074: A vulnerability allowing a high-privileged user to execute arbitrary code on the server.nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21