CVE-2026-32998CWE-233

This vulnerability in Veeam Service Provider Console allows for remote code execution

Critical · published May 28, 2026

CVSS v4.0
9.4
EPSS
1%
Percentile
42.1
In the wild
Unconfirmed
What it is

This vulnerability in Veeam Service Provider Console allows for remote code execution.

The record
Technical detail
CVSS v4.0
9.4 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.00517 · 42.1th percentile
Weakness
CWE-233 · Improper Handling of Parameters
Published
2026-05-28T04:01Z
EPSS history
Timeline
  • 28 MAY 04:01Z
    This vulnerability in Veeam Service Provider Console allows for remote code execution
    cvelistv5