# Multiple vulnerabilities in Veeam ONE and Service Provider Console allow remote arbitrary…

Published: 2026-05-28 · Severity: critical
Canonical: https://vorant.io/reports/ba175cce-b69e-4c30-b359-bcb5bb2c9d60/multiple-vulnerabilities-in-veeam-one-and-service-provider-console-allow-remote

> Multiple vulnerabilities in Veeam ONE and Service Provider Console allow remote arbitrary code execution; patches available.

CERT-FR has issued an advisory regarding multiple vulnerabilities discovered in Veeam backup and management products. The affected products include Veeam ONE versions prior to 13.0.2.6723 and Service Provider Console versions 9.2.1.x prior to 9.2.1.33875 and versions prior to 9.2.0.33215. These vulnerabilities enable remote arbitrary code execution and include at least one additional unspecified security issue.

The vendor has released security bulletins (kb4853, kb4856, kb4858) on May 27, 2026, providing patches to address these issues. At least one vulnerability has been assigned CVE-2026-32998. Organizations running affected versions should prioritize applying the available patches given the remote code execution capability.

Veeam products are widely deployed in enterprise backup and disaster recovery environments. Successful exploitation could grant attackers control over backup infrastructure, potentially leading to data exfiltration, ransomware deployment, or destruction of backup repositories.

## Mentioned in this report

- Vulnerabilities: CVE-2026-32998

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0657

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ba175cce-b69e-4c30-b359-bcb5bb2c9d60/multiple-vulnerabilities-in-veeam-one-and-service-provider-console-allow-remote.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
