Veeam security patch release for CVE-2026-58073
Security Patch Release
Summary
Hide ▲
Show ▼
Veeam released Service Provider Console 9.3.0.35057 to fix four vulnerabilities in the multi-tenant backup management console. The most serious are CVE-2026-58073, an unauthenticated credential-theft flaw, and CVE-2026-58072, an arbitrary file-write issue that can lead to remote code execution. The fixes apply to VSPC 9.2.1.33875 and earlier version 9 builds, and operators are told to upgrade to 9.3.0.35057.
Related Happenings
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch Release
H score29
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
RabbitMQ maintainers security patch release for CVE-2026-57219
Security Patch ReleaseAbout this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch Release
H score41
First: 06.07.2026 20:37
Last: 06.07.2026 20:37
Sources 1
About this happening:
The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch ReleaseAbout this happening: The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
Veeam security patch release for CVE-2026-44963
Security Patch Release
H score79
First: 09.06.2026 17:27
Last: 09.06.2026 17:27
Sources 1
About this happening:
Veeam released security updates for Veeam Backup & Replication to fix CVE-2026-44963, a critical flaw that could enable remote code execution on domain-joined ba...
Veeam security patch release for CVE-2026-44963
Security Patch ReleaseAbout this happening: Veeam released security updates for Veeam Backup & Replication to fix CVE-2026-44963, a critical flaw that could enable remote code execution on domain-joined ba...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Timeline
-
05.08.2026 17:27 2 articles · 2h ago
Veeam releases Service Provider Console 9.3.0.35057 to fix four flaws
Mitigation Patch UpdateVeeam released Service Provider Console 9.3.0.35057 on July 29 to fix four vulnerabilities in the multi-tenant backup management console, including CVE-2026-58073 and CVE-2026-58072. The build applies to VSPC 9.2.1.33875 and earlier version 9 builds.
Show sources
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — thehackernews.com — 05.08.2026 17:27
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — thehackernews.com — 05.08.2026 17:27
-
05.08.2026 17:27 1 articles · 2h ago
Veeam details four Service Provider Console vulnerabilities in build 9.3.0.35057
Initial DisclosureA security bulletin published August 4 detailed four Service Provider Console vulnerabilities fixed in build 9.3.0.35057. CVE-2026-58073 is an unauthenticated flaw that can impersonate a managed agent and expose that agent's credentials, while CVE-2026-58072 is an arbitrary file-write issue on the management server that can lead to remote code execution; the bulletin also listed CVE-2026-58067 and CVE-2026-58071 and directed operators to upgrade to 9.3.0.35057.
Show sources
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — thehackernews.com — 05.08.2026 17:27