Skip to content
Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks

Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks

First seen 5 Aug 2026, 19:31 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 6, 2026 at 16:10 UTC
  • Multiple critical vulnerabilities in Veeam software allow remote code execution and credential theft.
  • CVSS scores range from 8.4 to 10.0, indicating high severity and potential for exploitation.
  • Users are advised to apply patches immediately to mitigate risks associated with these vulnerabilities.

On August 5, 2026, Veeam disclosed multiple critical vulnerabilities affecting Veeam ONE and Veeam Service Provider Console. The vulnerabilities include remote unauthenticated code execution, file read access, and SQL injection, with CVSS scores ranging from 8.4 to 10.0. Affected systems include Veeam ONE 13.1 and the Veeam Service Provider Console, which could allow attackers to execute arbitrary code, impersonate agents, and exhaust host memory. These vulnerabilities were reported through HackerOne and discovered during internal testing. Patches have been released to address these issues, and users are urged to update their systems immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-08-05
Veeam discloses vulnerabilities
Veeam announced critical vulnerabilities in Veeam ONE and Service Provider Console, affecting remote code execution and credential theft.
Veeam
2026-08-05
Patches released
Veeam released patches to fix the identified vulnerabilities, urging users to update their systems immediately.
Veeam

More articles in this cluster (4)

Following this threat?

Track CVE-2026-58073 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed