Skip to content
According to a post

According to a post

www.veeam.com August 7, 2026

Now you’re less likely to miss what’s been brewing in our knowledge base with this weekly digest

Oops! Something went wrong. Please, try again later.

Please, try again later.

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials.

Severity: Critical CVSS v4.0 Score: 9.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Source: Reported through HackerOne.

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remote code execution.

Severity: Critical CVSS v4.0 Score: 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Source: Reported through HackerOne.

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause a denial of service.

Severity: High CVSS v4.0 Score: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Source: Discovered during internal testing.

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API as Portal Administrator during a short window after an administrator session begins.

Severity: High CVSS v4.0 Score: 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Source: Discovered during internal testing.

These vulnerabilities were fixed starting with the following build:

If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.

To submit feedback regarding this article, please click this link: Send Article Feedback To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Your feedback has been received and will be reviewed.

Please, try again later.

Please try select less .

This form is only for KB Feedback/Suggestions, if you need help with the software open a support case

Your feedback has been received and will be reviewed.

Oops! Something went wrong. Please, try again later.

Please, try again later.

Extracted Entities

Attack Types (1)