ReviewHigh
CVE-2026-64632
Veeam ONE
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
- CVSS
- 8.5
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.27
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
The CVSS severity warrants an early asset and exposure review.
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
Confirm exposure before applying a vendor-supported change.
Confirm that Veeam ONE and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.