CVE-2022-26501: Veeam Backup & Replication Remote Code Execution
Veeam Backup & Replication Remote Code Execution Vulnerability. The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
- CISA KEV-listed (remediation due 2023-01-03)
- used in ransomware campaigns
- EPSS 75.4% (98.9% percentile)