Veeam Vulnerabilities and Affected Products
Vulnerabilities associated with Service Provider Console.
Products
Clear product- One18 vulnerabilities
- Backup & Replication16 vulnerabilities
- Backup and Replication14 vulnerabilities
- Backup and Recovery13 vulnerabilities
- Service Provider Console10 vulnerabilities
- service_provider_console7 vulnerabilities
- backup_\&_replication6 vulnerabilities
- Veeam Service Provider Console5 vulnerabilities
- agent4 vulnerabilities
- backup_enterprise_manager4 vulnerabilities
- backup_and_replication3 vulnerabilities
- Recovery Orchestrator3 vulnerabilities
- Agent for Windows2 vulnerabilities
- Availability Orchestrator2 vulnerabilities
- Backup for Microsoft Azure2 vulnerabilities
- One Agent2 vulnerabilities
- Software Appliance2 vulnerabilities
- veeam_backup_\&_replication2 vulnerabilities
- Agent for Microsoft Windows1 vulnerability
- Backup and Recovery1 vulnerability
- Backup for AWS1 vulnerability
- Backup for Google Cloud1 vulnerability
- Backup for Microsoft Windows1 vulnerability
- Backup for Nutanix AHV1 vulnerability
- Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-58072CRITICAL | Generated title:Veeam Service Provider Console Arbitrary File Write to Remote Code ExecutionA vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. CWE-22Aug 4, 2026 | CVSS9.0v4.0 | EPSS0.376% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58073CRITICAL | Generated title:Veeam Service Provider Console Authentication Bypass via ImpersonationA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. CWE-288Aug 4, 2026 | CVSS9.5v4.0 | EPSS0.224% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58071HIGH | Generated title:Veeam Service Provider Console Authentication Bypass via Proxied APIA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. CWE-306Aug 4, 2026 | CVSS8.2v4.0 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58067HIGH | Generated title:Veeam Service Provider Console Memory Allocation Denial of ServiceA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. CWE-789Aug 4, 2026 | CVSS8.7v4.0 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64635MEDIUM | Generated title:Veeam Service Provider Console Forgot Password ReturnUrl Open Redirect and Account TakeoverImproper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account. CWE-640Jul 30, 2026 | CVSS5.3v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32998CRITICAL | Generated title:Veeam Service Provider Console Remote Code Execution VulnerabilityThis vulnerability in Veeam Service Provider Console allows for remote code execution. CWE-233May 28, 2026 | CVSS9.4v4.0 | EPSS0.403% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42448CRITICAL | Veeam Service Provider Console Remote Code Execution VulnerabilityFrom the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine. CWE-94Dec 11, 2024 | CVSS9.9v3.0 | EPSS20.1% | PoCs1 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2024-45206MEDIUM | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. CWE-918Dec 4, 2024 | CVSS6.5v3.0 | EPSS0.242% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42449HIGH | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine. CWE-732Dec 4, 2024 | CVSS7.1v3.0 | EPSS5.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29212CRITICAL | Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine. CWE-502May 13, 2024 | CVSS9.9v3.0 | EPSS1.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |