Find notable cyber news and cases, enriched with sources, timelines, and signals.

Veeam security patch release for CVE-2026-58073

Security Patch Release
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

Veeam released Service Provider Console 9.3.0.35057 to fix four vulnerabilities in the multi-tenant backup management console. The most serious are CVE-2026-58073, an unauthenticated credential-theft flaw, and CVE-2026-58072, an arbitrary file-write issue that can lead to remote code execution. The fixes apply to VSPC 9.2.1.33875 and earlier version 9 builds, and operators are told to upgrade to 9.3.0.35057.

Related Happenings

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

RabbitMQ maintainers security patch release for CVE-2026-57219

Security Patch Release
H score29 First: 14.07.2026 16:48 Last: 14.07.2026 16:48 Sources 1

About this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...

Linux kernel stable maintainers security patch release for CVE-2026-53359

Security Patch Release
H score41 First: 06.07.2026 20:37 Last: 06.07.2026 20:37 Sources 1

About this happening: The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...

Veeam security patch release for CVE-2026-44963

Security Patch Release
H score79 First: 09.06.2026 17:27 Last: 09.06.2026 17:27 Sources 1

About this happening: Veeam released security updates for Veeam Backup & Replication to fix CVE-2026-44963, a critical flaw that could enable remote code execution on domain-joined ba...

Ivanti security patch release for CVE-2026-8043

Security Patch Release
H score25 First: 18.05.2026 13:54 Last: 18.05.2026 13:54 Sources 1

About this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...

Timeline

  1. 05.08.2026 17:27 2 articles · 13d ago

    Veeam releases Service Provider Console 9.3.0.35057 to fix four flaws

    Mitigation Patch Update

    Veeam released Service Provider Console 9.3.0.35057 on July 29 to fix four vulnerabilities in the multi-tenant backup management console, including CVE-2026-58073 and CVE-2026-58072. The build applies to VSPC 9.2.1.33875 and earlier version 9 builds.

    Show sources
  2. 05.08.2026 17:27 1 articles · 13d ago

    Veeam details four Service Provider Console vulnerabilities in build 9.3.0.35057

    Initial Disclosure

    A security bulletin published August 4 detailed four Service Provider Console vulnerabilities fixed in build 9.3.0.35057. CVE-2026-58073 is an unauthenticated flaw that can impersonate a managed agent and expose that agent's credentials, while CVE-2026-58072 is an arbitrary file-write issue on the management server that can lead to remote code execution; the bulletin also listed CVE-2026-58067 and CVE-2026-58071 and directed operators to upgrade to 9.3.0.35057.

    Show sources