Multiple vulnerabilities in Veeam products (August 5, 2026)
Multiple vulnerabilities have been discovered in Veeam products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities in Veeam products enabling remote arbitrary code execution, privilege escalation, and denial of service.
- Who is affected
- Users of Veeam products affected by CVE-2026-64633, CVE-2026-58067, CVE-2026-58072, CVE-2026-58075, CVE-2026-58073, CVE-2026-58074, CVE-2026-58071, CVE-2026-64630.
- Urgency
- Critical; multiple RCE and privilege escalation vulnerabilities pose immediate risk.
- Action
- Apply Veeam security updates as announced on August 5, 2026.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0968/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-646330.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580670.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580720.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580750.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580730.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580740.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580710.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-646300.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-646340.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-646310.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64633 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58067 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58072 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58075 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58073 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58074 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58071 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64630 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64634 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64631 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0276 [1.00] [M/H] Vulnerabilities patched in Veeam Service Provider Consolencsc-nl
- high[NEW] [high] Veeam ONE: Multiple Vulnerabilitiescert-bund
- unknownCVE-2026-64634: A vulnerability allowing local privilege escalation to the Reporter service context.nvd
- unknownCVE-2026-64633: A vulnerability allowing remote unauthenticated code execution on the agent host.nvd
- unknownCVE-2026-64631: A vulnerability allowing a low-privileged user to inject SQL and extract database contents.nvd
- unknownCVE-2026-64630: A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a …nvd
- unknownCVE-2026-58075: A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, wh…nvd
- unknownCVE-2026-58074: A vulnerability allowing a high-privileged user to execute arbitrary code on the server.nvd
- unknownCVE-2026-58073: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impe…nvd
- unknownCVE-2026-58072: A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the managem…nvd
- unknownCVE-2026-58071: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to acce…nvd
- unknownCVE-2026-58067: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exha…nvd
More from CERT-FR Avis de sécurité
- unknownVulnerability in Sonicwall SonicOS (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Wallix products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Cisco products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in Nextcloud products (August 6, 2026)2026-08-06
- unknownMultiple vulnerabilities in KeyCloak (August 6, 2026)2026-08-06