# Veeam Patches Backup & Replication, ONE Flaws

Published: 2026-08-26 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/41b0c6e0-a358-5668-bfc7-a2aace660938/veeam-patches-backup-replication-one-flaws

> ANSSI advisory: Veeam Backup & Replication and Veeam ONE contain flaws allowing data confidentiality breaches and security policy bypass.

ANSSI (CERT-FR) published an advisory covering multiple vulnerabilities in Veeam products, specifically Veeam Backup & Replication versions 13.x prior to 13.0.3 and Veeam ONE versions 13.x prior to 13.0.2 Patch 1. The flaws, tracked as CVE-2026-58070 and CVE-2026-65641, could allow an attacker to compromise data confidentiality and bypass security policy controls. No indication of active exploitation is provided in the advisory.

Veeam has released security bulletins (kb4902 and kb4905, dated 25 August 2026) with patches addressing these issues. Organizations running affected versions of Veeam Backup & Replication or Veeam ONE should apply the vendor-supplied updates promptly, given that backup infrastructure is a high-value target for attackers seeking to exfiltrate sensitive data or disable recovery capabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2026-58070, CVE-2026-65641

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1080

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/41b0c6e0-a358-5668-bfc7-a2aace660938/veeam-patches-backup-replication-one-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
