logo

Warning: Multiple Critical Vulnerabilities in Veeam Service Provider Console, Patch Immediately!

ID: 75b3eab2-18fe-5f17-ac96-dbaadeabb20e

STIX ID: report--75b3eab2-18fe-5f17-ac96-dbaadeabb20e

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
78/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

...
...

Veeam published a security advisory for Service Provider Console (up to 9.2.1.33875 and earlier 9.x builds) disclosing four critical/high vulnerabilities—including authentication bypass (CVE-2026-58073), path traversal leading to arbitrary file write/RCE (CVE-2026-58072), memory exhaustion DoS (CVE-2026-58067), and unauthorized proxied API access (CVE-2026-58071); fixes are available in 9.3.0.35057 and organizations are urged to apply patches and increase monitoring due to the high impact on confidentiality, integrity, and availability despite no known active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.