CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-58072: Arbitrary File Write Leading to RCE in Veeam Service Provider Console

August 5, 2026

CVE-2026-58072 (CVSS 9.0) is a critical arbitrary file write vulnerability on the Veeam Service Provider Console management server that can lead to remote code execution. It requires a low-privilege account. Fixed in build 9.3.0.35057.