Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-26501

Veeam | Backup & ReplicationAdded 2022-12-13Remediation Deadline 2023-01-03Active Ransomware Campaign

Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-306

References