TL;DR
Veeam patched four flaws in Veeam Service Provider Console. Two are critical. One is an unauthenticated credential-theft bug rated CVSS 9.5. The other is an arbitrary file write that enables remote code execution. Service providers should update to build 9.3.0.35057 now.
Why it matters
Veeam Service Provider Console runs multi-tenant backup management for hosting and MSP environments. So one compromised console can expose many downstream customers. That makes it a prime ransomware target. Both critical bugs need no authentication, which lowers the bar for attackers. Worse, attackers often chain such flaws. Stolen agent credentials plus a file-write bug could hand over the whole console.
How the attack works
The advisory describes CVE-2026-58073 as a flaw that lets “an unauthenticated attacker to impersonate a managed agent and obtain that agent’s credentials.” With those credentials, an attacker can push deeper into managed estates. Separately, CVE-2026-58072 allows arbitrary file writes on the management server. That primitive can lead to remote code execution. The write bug is potent because the management server sits at the center of every managed tenant. Veeam has not shared deeper technical details. The company also reported no exploitation in the wild, and no public proof-of-concept has surfaced.
Other fixes in this release
Two more flaws are rated high. CVE-2026-58067 lets an unauthenticated attacker exhaust host memory and trigger a denial of service, rated 8.7. CVE-2026-58071 briefly exposes a proxied appliance API to the Portal Administrator role right after an admin session starts, rated 8.2.
Affected versions
The flaws affect Veeam Service Provider Console 9.2.1.33875 and all earlier version 9 builds.
Patch and mitigation
Update to Veeam Service Provider Console 9.3.0.35057, which fixes all four. No standalone workaround exists. Until you patch, limit network access to the console and its portal. For full details, read Veeam’s KB4893 advisory.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.