Junglewise Threat Intelligence

CVE-2026-58067: Veeam Service Provider Console memory exhaustion denial of service

CVE-2026-58067 · Severity: info · CVSS 8.7 · Published 2026-08-04

Technologies: Veeam Service Provider Console. Vendors: Veeam.

Executive brief

Veeam Service Provider Console is a management platform used by managed service providers to oversee backup and disaster recovery operations. An unauthenticated attacker can trigger excessive memory consumption on the management server, causing the service to become unavailable and disrupting backup operations for all managed customers.

Technical details

This is a denial-of-service vulnerability in Veeam Service Provider Console that allows an unauthenticated attacker over the network to exhaust host memory without authentication or user interaction required. The vulnerability affects Veeam Service Provider Console version 9.2.1.33875 and all earlier version 9 builds. By exhausting memory resources, an attacker can cause the management server to become unresponsive and unavailable. The issue was discovered during internal testing and has been fixed starting with version 9.3.0.35057.

Affected products

  • Veeam Service Provider Console 9.2.1.33875 and earlier 9.x versions

Timeline

  • 2026-08-04: disclosed
  • 2026-08-04: patched: Fixed in version 9.3.0.35057

References

Related threats