Skip to content
COOEY

EXPOSURES › CVE-2022-26500

CVE-2022-26500

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-12-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26500 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Unauthenticated remote attackers could execute arbitrary code via the Veeam Backup & Replication Distribution Service, enabling ransomware deployment.

Veeam's Backup & Replication software allowed unauthenticated users to access internal API functions, leading to remote code execution. This is critical for DIB organizations because backup systems are high-value targets for ransomware, and a compromise could destroy recovery capabilities. Organizations must ensure all Veeam components are patched and monitored for exploitation attempts.

Shame score — A critical RCE in a widely deployed backup product was actively exploited in the wild for ransomware, demonstrating severe negligence in patching and API security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.