Veeam disclosed no new vulnerabilities in September 2026. That is the good news. The work is still August’s advisories — and two of the builds you were told to move to have since been superseded, so an estate patched in August may already be behind. All severities below are CVSS v4.0, as Veeam publishes them.
Patch now: Veeam Service Provider Console
Target build: 9.3.0.35706, released 4 September 2026. Note this has changed: the August advisory pointed at 9.3.0.35057, which itself shipped on 29 July. If you patched to 35057 you are protected against the CVEs below, but you are a release behind. The September build is bug fixes only — agent-connection scalability at large estates, VMware Cloud Director job mapping in the Backup & Replication integration, and REST API company-usage latency — with no new CVEs.
Affected: 9.2.1.33875 and all earlier version 9 builds.
- CVE-2026-58073 (Critical, 9.5) — an unauthenticated attacker could impersonate a managed agent and obtain that agent’s credentials. For a service provider managing many customer environments, this remains the highest-priority item.
- CVE-2026-58072 (Critical, 9.0) — arbitrary file write on the management server, which can lead to remote code execution.
- CVE-2026-58067 (High, 8.7) — an unauthenticated attacker could exhaust host memory and cause a denial of service.
- CVE-2026-58071 (High, 8.2) — access to the proxied appliance API as Portal Administrator during a short window after an administrator session begins.
Detail: KB4893. Release information: KB4788.
Patch now: Veeam ONE
Target build: 13.1.0.7233, or 13.0.2.7159 if you are staying on 13.0.
CVE-2026-65641 (Critical, 9.3) allows an unauthenticated network attacker to coerce SMB authentication from the service account. It affects 13.1.0.7034 and all earlier version 13 builds. Version 12 is not affected by this one. Note that 13.1.0.7233 is also required before Veeam ONE can monitor Veeam Backup & Replication 13.0.3.
Behind it sits the most severe item of the period. CVE-2026-64633 (Critical, 10.0) allows remote unauthenticated code execution on the agent host, affecting 13.0.2.6723 and all earlier version 13 builds. It is fixed in 13.1.0.7034 and in 13.0.2 Patch 1 (13.0.2.7159), so both recommended builds above already contain the fix.
The same advisory carries six further vulnerabilities:
- CVE-2026-58075 (High, 8.7) — arbitrary file read leading to local privilege escalation.
- CVE-2026-58074 (High, 8.6) — remote code execution on the server by a high-privileged user.
- CVE-2026-64631 (High) — SQL injection. Veeam publishes 8.6 and the NVD entry shows 8.5 against an identical vector, so treat it as High and do not quote a precise figure.
- CVE-2026-64632 (High, 8.5) — NTLM credential capture of the Reporter service account.
- CVE-2026-64634 (High, 8.4) — local privilege escalation into the Reporter service context.
- CVE-2026-64630 (Medium, 5.3) — report data accessible outside the intended shared-link scope.
Version 12 is not off the hook. Three of those six — CVE-2026-58074, CVE-2026-64631 and CVE-2026-64632 — also affect 12.3.0.4670 and all earlier version 12 builds, fixed in 12.3 Patch 1 (build 12.3.0.7165). If you have stayed on Veeam ONE 12 on the basis that version 12 was unaffected, that is true only of CVE-2026-65641.
Patch soon: Veeam Backup & Replication
Target build: 13.1.0.411 or 13.0.3.63.
CVE-2026-58070 (Medium, 6.8) caused guest OS credentials used for Application-Aware Processing to be written to logs in cleartext on the guest machine. It affects 13.0.2.29 and all earlier version 13 builds, on Windows-based deployments and on the Veeam Software Appliance. Version 12.x is not affected. The attack vector is local, which is what holds it to Medium — but patching only stops further logging. Credentials already written to guest logs should be rotated.
Detail: KB4902.
A note on the scores
Veeam scores these in CVSS v4.0 only; there are no v3.1 figures for any of them. The National Vulnerability Database entries carry the same v4.0 numbers because NVD is republishing the CNA’s score rather than assigning its own, and CVE-2026-58070 has no NVD record at all. If your vulnerability management process expects an independent NVD rating before you act, these will not have one.
Also released in September
- Veeam Backup for Microsoft 365 8.6 (build 8.6.0.1102, 14 September). The timely part: it assigns permissions automatically for backup app registrations in Entra ID ahead of the retirement of EWS in Exchange Online on 1 October 2026. It also adds PowerShell cmdlets to remediate data in affected repositories, and object storage repository maintenance mode via PowerShell and REST. Source: KB4913.
- Veeam Plug-In for KubeVirt 1.0 (build 13.1.0.428, 8 September) — the Red Hat OpenShift Virtualization support promised at the 13.1 launch. Veeam’s download page lists the same build as the Red Hat OpenShift plug-in, so expect both names. Source: KB4914.
- Veeam Plug-In for Scale Computing HyperCore 4.1 (build 13.4.1.328, 24 September).
There was no new Backup & Replication build in September. 13.1.1.18 was released on 12 August; the September dates on Veeam’s download page are ISO repacks of that build.
Context: Veeam Data Platform 13.1
Worth a mention because it sets up much of the above, though it is a late-July release rather than an August or September one. Backup & Replication 13.1 brought more than 70 new features, including out-of-the-box support for six more hypervisors — Red Hat OpenShift Virtualization, Sangfor aSV, XCP-ng, Citrix XenServer, VergeIO and Platform9 — taking the total to 14. Application protection extended to Epic EHR, IBM Db2 on Windows and Oracle Database 26ai, with an Application Backup Repository for custom applications. On the security side: malware scanning for NAS, expanded Azure threat detection, automated Active Directory forest recovery, recovery point validation before restore, hybrid FIPS with post-quantum cryptography processing, and NAS archive tiers on AWS S3 Glacier and Azure Archive.
Recovery Orchestrator 13.1 improved Clean Room recovery, with read-only access to backup repositories keeping Clean Room plans current, standalone Hyper-V hosts as a recovery target, cross-platform restore from vSphere VM backups, and restoration of Hyper-V backups to Azure Cloud Plans. Veeam Data Cloud Vault Archive arrived alongside it: a lower-cost archive tier on Azure Blob Archive with immutability, AES-256 encryption and logical air-gapping, able to move GFS restore points automatically from Vault Standard.
Not sure where you stand?
Arrosoft is a Gold Veeam Service Provider and manages Veeam environments for partners across APAC and North America. If you want your build versions checked against these advisories — including whether an August patch has already been superseded — talk to us.
