Skip to content
COOEY

EXPOSURES › CVE-2022-26501

CVE-2022-26501

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-12-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26501 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Unauthenticated remote attackers could execute arbitrary code via the Veeam Backup & Replication Distribution Service, enabling ransomware deployment.

Veeam's Backup & Replication software allowed unauthenticated users to access internal API functions, leading to remote code execution. This is critical for DIB organizations because backup systems are high-value targets for ransomware; a compromise could result in data loss, operational disruption, and severe compliance failures under NIST 800-171. Organizations must ensure all backup software is patched and monitored for exploitation attempts.

Shame score — A critical RCE vulnerability in widely deployed backup software was actively exploited in the wild for ransomware, demonstrating severe negligence in patching and API security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.