DEV Community

Cover image for Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Summary

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

Take Action:

If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)