Remote Code Execution (RCE) in Veeam Service Provider Console
CVE-2026-32998 Published on May 28, 2026

This vulnerability in Veeam Service Provider Console allows for remote code execution.

NVD

Weakness Type

Improper Handling of Parameters

The software does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.


Affected Versions

Veeam Service Provider Console:

Exploit Probability

EPSS
0.40%
Percentile
31.89%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.