ctipilot.ch

Veeam Service Provider Console — unauthenticated host-memory exhaustion denial of service (CVSS v4.0 8.7); fixed in 9.3.0.35057

cve · CVE-2026-58067

Coverage timeline
1
first 2026-08-06 → last 2026-08-06
Peak priority
notable
1 notable
Sources cited
4
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Related entities below
ATT&CK techniques
2
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Veeam ONEVeeam Service Provider Console

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-06/veeam-service-provider-console-veeam-one-ten-cves · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-08-06/veeam-service-provider-console-veeam-one-ten-cves · ATT&CK page ↗

Story timeline

  1. 2026-08-06Veeam Service Provider Console and Veeam ONE — ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host
    trending-vulnerabilitiesVeeam patches ten flaws across the console that manages backups and the platform that monitors them

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • veeam.com2 (50%)
  • advisories.ncsc.nl1 (25%)
  • cert.ssi.gouv.fr1 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Veeam Service Provider Console — unauthenticated host-memory exhaustion denial of service (CVSS v4.0 8.7); fixed in 9.3.0.35057 (1)

2026-08-06 · view entry permalink →

NOTABLECVE-2026-64633 +9NATOA2

Veeam Service Provider Console and Veeam ONE — ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host

Veeam published two security bulletins on 2026-08-04 covering ten vulnerabilities. CERT-FR carried both products and the full set the following day (CERT-FR, 2026-08-05); NCSC-NL's advisory of the same date covers only Service Provider Console and its four CVEs, and does not mention Veeam ONE or the 10.0 agent-host flaw at all (NCSC-NL, 2026-08-05) — worth knowing if your patch intake is driven by a single national feed. In Veeam ONE, CVE-2026-64633 is described by the vendor as allowing remote unauthenticated code execution on the agent host and is scored CVSS v4.0 10.0 with no privileges and no user interaction required (Veeam, 2026-08-04). Its siblings in the same product are CVE-2026-58075 (8.7), an unauthenticated arbitrary file read from the host that the vendor says can be leveraged to escalate privileges locally; CVE-2026-58074 (8.6), arbitrary code execution on the server by a high-privileged user; CVE-2026-64631 (8.6), SQL injection by a low-privileged user extracting database contents; CVE-2026-64634 (8.4), local privilege escalation into the Reporter service context; and CVE-2026-64630 (5.3), retrieval of report data outside a shared link's scope (Veeam, 2026-08-04). All affect Veeam ONE 13.0.2.6723 and all earlier version 13 builds, and all are resolved in 13.1.0.7034 (Veeam, 2026-08-04).

In Veeam Service Provider Console, CVE-2026-58073 (CVSS v4.0 9.5) allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials — though the vendor's own vector records high attack complexity, which is the one meaningful brake on the four (Veeam, 2026-08-04). CVE-2026-58072 (9.0) permits arbitrary file write on the management server leading to remote code execution; CVE-2026-58067 (8.7) lets an unauthenticated attacker exhaust host memory for denial of service; and CVE-2026-58071 (8.2) allows an unauthenticated attacker to reach the proxied appliance API as Portal Administrator during a short window after an administrator session begins (Veeam, 2026-08-04). These affect Service Provider Console 9.2.1.33875 and all earlier version 9 builds, resolved in 9.3.0.35057 (Veeam, 2026-08-04).

No party — vendor or CERT — reports exploitation of any of the ten. The reason this still warrants attention ahead of the ordinary patch cycle is what the two products are: Service Provider Console is the multi-tenant management plane through which service providers administer customer backup estates, and Veeam ONE is the monitoring platform over that same estate. An agent-credential impersonation flaw on the former and an unauthenticated code-execution flaw on the latter both land on infrastructure that holds broad, standing access into the systems an organisation would rely on to recover — and backup infrastructure is a recognised pre-encryption target rather than a bystander.

A vulnerability allowing remote unauthenticated code execution on the agent host.

Veeam (KB4892) 2026-08-04

impersonate a managed agent and obtain that agent's credentials

Veeam (KB4893) 2026-08-04
vulnerability06 Aug 04:11Zmulti-sourceOpen finding ↗