CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64635

mediumCVSS 5.3covered by 1 sourcefirst seen 2026-07-30
Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.

⚡ Watch CVE-2026-64635

Get an email if CVE-2026-64635 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-64635

CVE.org record

Embed the live status

CVE-2026-64635 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64635 status](https://www.csirts.com/badge/CVE-2026-64635)](https://www.csirts.com/cve/CVE-2026-64635)