RaqibCTI
CVE

CVE-2022-26500

P1⬤ KNOWN RANSOMWARE USE
Veeam Backup & Replication Remote Code Execution Vulnerability
Veeam · Backup & Replication
Date added (CISA)
2022-12-13
Remediation due
2023-01-03
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date

Description

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

Source: NVD ↗ · CISA KEV Catalog ↗