EXPOSURES › CVE-2022-26501
CVE-2022-26501
CRITICAL ⌖ ON CISA KEV · EXPLOITEDUnauthenticated remote attackers could execute arbitrary code via the Veeam Backup & Replication Distribution Service, enabling ransomware deployment.
Veeam's Backup & Replication software allowed unauthenticated users to access internal API functions, leading to remote code execution. This is critical for DIB organizations because backup systems are high-value targets for ransomware; a compromise could result in data loss, operational disruption, and severe compliance failures under NIST 800-171. Organizations must ensure all backup software is patched and monitored for exploitation attempts.
Shame score — A critical RCE vulnerability in widely deployed backup software was actively exploited in the wild for ransomware, demonstrating severe negligence in patching and API security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.