CVE-2022-26500βVeeam Backup & Replication Remote Code Execution Vulnerability
PUBLISHEDvulnerability record
2022-12-13 Β· last modified June 21, 2025
Metadata
Vulnerability Name
Veeam Backup & Replication Remote Code Execution Vulnerability
Description
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.