Our takeVeeam published fixes for critical flaws in Backup & Replication (pre-13.0.2.29), ONE (pre-13.0.2.6723), and Service Provider Console (pre-9.2.1.33875). Patch immediately.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Veeam published fixes for vulnerabilities in Backup & Replication (pre-13.0.2.29), ONE (pre-13.0.2.6723), and Service Provider Console (pre-9.2.1.33875). Apply the updates on your normal emergency change path.
What this means for you — Lean IT orgs:If you run Veeam Backup & Replication, Veeam ONE, or Service Provider Console, update to the fixed versions immediately — these patches address actively exploited vulnerabilities.
What this means for you — MSP:Check every client running Veeam Backup & Replication (pre-13.0.2.29), ONE (pre-13.0.2.6723), or Service Provider Console (pre-9.2.1.33875) and deploy the patches; the vulnerabilities are under active exploitation.
What this means for you — Researcher:Veeam advisory AV26-513 details vulnerabilities in Backup & Replication, ONE, and Service Provider Console that are under active exploitation per CCCS reporting. Review the open-source repo for full technical detail.