CVE-2026-58073 (CVSS 9.5) is a critical vulnerability in Veeam Service Provider Console that allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. The attack complexity is high. Fixed in build 9.3.0.35057.