Skip to main content
Question

OpenSSL CVE-2026-31789 Out of Bounds Write Vulnerability - Veeam Agent for Windows [v13.0.3.1220]

  • July 23, 2026
  • 4 comments
  • 11 views

vAdmin
Forum|alt.badge.img+2

Hi All,

 

Would it be possible to replace or update the OpenSSL component only on the Veeam Agent for Windows [v13.0.3.1220] due to the Critical bug below, or is it better to wait until Veeam released the latest update ?

 

Recommended Action: Download and install patches as instructed

Description:A heap buffer overflow from converting large OCTET STRINGs to hex on 32 bit OpenSSL may crash or allow code execution; caused by 32 bit multiplication overflow; affects non FIPS OpenSSL 3.x on 32 bit systems.

Affected Products:OpenSSL

CVE IDs:CVE-2026-31789

Vendor Information:https://www.openssl.org/news/vulnerabilities.html

Vendor Patch Download:https://wiki.openssl.org/index.php/Binaries

 

Thank you,

4 comments

coolsport00
Forum|alt.badge.img+23
  • Veeam Legend
  • July 23, 2026

Not really sure on that. Your best bet is to contact Veeam Support for this question ​@vAdmin .


vAdmin
Forum|alt.badge.img+2
  • Author
  • Influencer
  • July 23, 2026

Yes, that’s the question I ask them as well.

let see what they come up with.

Thank you, ​@coolsport00 


coolsport00
Forum|alt.badge.img+23
  • Veeam Legend
  • July 23, 2026

Nice. Keep us posted!


Chris.Childerhose
Forum|alt.badge.img+22

I would assume the 13.1 release to come this month will have an updated Agent with a fix for this, but let’s see what they say.