Multiple vulnerabilities in Veeam ONE and Service Provider Console allow remote arbitrary…
Multiple vulnerabilities in Veeam ONE and Service Provider Console allow remote arbitrary code execution; patches available.
CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in Veeam backup and management products. The affected products include Veeam ONE versions prior to 13.0.2.6723 and Service Provider Console versions 9.2.1.x prior to 9.2.1.33875 and versions prior to 9.2.0.33215. These vulnerabilities enable remote arbitrary code execution and include at least one additional unspecified security issue.
The vendor has released security bulletins (kb4853, kb4856, kb4858) on May 27, 2026, providing patches to address these issues. At least one vulnerability has been assigned CVE-2026-32998. Organizations running affected versions should prioritize applying the available patches given the remote code execution capability.
Veeam products are widely deployed in enterprise backup and disaster recovery environments. Successful exploitation could grant attackers control over backup infrastructure, potentially leading to data exfiltration, ransomware deployment, or destruction of backup repositories.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0657
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free