LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26501: Veeam Backup & Replication Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 13, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26501 to its Known Exploited Vulnerabilities catalog on Dec 13, 2022, with a federal patch deadline of Jan 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may…

CVE-2022-26501 is a remote code execution vulnerability in Veeam Backup & Replication. The Veeam Distribution Service allows unauthenticated users to reach internal API functions; a remote attacker can send input that may result in uploading and executing malicious code.

Backup infrastructure is high-value because it often holds credentials, snapshots, and recovery paths for the rest of the estate. The vulnerability is known to have been used by ransomware operators, so unpatched instances should be treated as urgent. Confirm every version, configuration, and fix detail against the vendor advisory.

How it works

The underlying weakness is CWE-306, Missing Authentication for Critical Function. The Distribution Service exposes internal API functions without requiring authentication.

An attacker who can reach the service sends crafted input to those API functions. Because authentication is absent, the input can lead to file upload and subsequent code execution on the host running the service. Exact request formats, ports, and preconditions are not detailed here; they must be taken from the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

Veeam Backup & Replication is typically installed on dedicated Windows servers or virtual machines that manage backups of hypervisors, servers, and endpoints. The Distribution Service is a component of that application.

How to remediate

Apply the updates supplied by Veeam according to the vendor instructions for this CVE. CISA’s required action is simply to apply those updates.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls that address the missing-authentication nature of the flaw.

If your data may have been exposed

Actively exploited vulnerabilities of this type, including those with known ransomware use, frequently lead to broader compromise of backup data, credentials, or adjacent systems. If exploitation is suspected, isolate the affected hosts, preserve logs and forensic images, and follow your incident-response plan. Separately, you can run a free exposure scan of your email addresses to check whether they appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVeeam · Backup & Replication
WeaknessCWE-306
Added to CISA KEVDec 13, 2022
Federal patch deadlineJan 3, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities