LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26500: Veeam Backup & Replication Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 13, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26500 to its Known Exploited Vulnerabilities catalog on Dec 13, 2022, with a federal patch deadline of Jan 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may…

CVE-2022-26500 is a remote code execution vulnerability in Veeam Backup & Replication. It stems from the Veeam Distribution Service allowing unauthenticated users to reach internal API functions; a remote attacker can supply input that may result in uploading and executing malicious code. This matters because backup infrastructure often holds privileged access to production systems and sensitive data, and the vulnerability is known to have been used in ransomware activity.

Defenders should treat any internet-reachable or poorly segmented Veeam Backup & Replication deployment as high priority until the vendor update is confirmed applied. Specifics of affected builds and exact attack paths must be verified against the vendor advisory.

How it works

The weakness is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In this case the Veeam Distribution Service exposes internal API functions without authentication. An unauthenticated remote attacker can send crafted input to those functions. Because the service does not properly constrain the input, the attacker may be able to cause the upload of attacker-controlled content and subsequent execution of that content on the host.

No further exploit mechanics are described in the public summary; treat any claim of specific payloads or sequences as unverified until confirmed in the vendor advisory or a trusted analysis. The practical outcome is remote code execution under the privileges of the Veeam service, which is typically high.

Am I affected? How to find it in your systems

Veeam Backup & Replication is commonly installed on dedicated backup servers, management hosts, or virtual appliances that communicate with production hypervisors, storage, and agents. Inventory every host that runs the Veeam Backup & Replication application or the Distribution Service component.

How to remediate

Apply the updates supplied by Veeam for Backup & Replication exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; that remains the primary fix.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this type have been leveraged in ransomware campaigns, which can lead to encryption, data theft, or both. If the affected Veeam host was reachable and unpatched during the period of known exploitation, treat it as a potential compromise: isolate the host, preserve forensic images, rotate credentials that the backup service could access, and examine backup repositories for unauthorized changes. Separately, you can run a free exposure scan of your email addresses against known breach data sets to determine whether any associated accounts already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVeeam · Backup & Replication
WeaknessCWE-22
Added to CISA KEVDec 13, 2022
Federal patch deadlineJan 3, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities