We would like to bring your attention to the following unauthenticated remote code execution vulnerability within Veeam Backup & Replication. This issue is being tracked as CVE-2022-26500 & CVE-2022-26501 and has been given the CVSS v3 score of 9.8.
At this time we are unaware of any proof of concept attacks or exploits for this issue being available in the wild, we will continue to monitor the situation around this.
Am I Effected?
Versions of Veeam prior to the following versions are known to be vulnerable (including the unsupported version 9.5):
-
11a (build 11.0.1.1261 P20220302)
-
10a (build 10.0.1.4854 P20220304)
Remediation
Apply the patches provided by Veeam to your Veeam Backup and Replication Server:
References
-
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26500
-
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26501
CovertSwarm named in two Gartner® Hype Cycle™ reports in the Red Teaming as a Service category
CovertSwarm has been named a Sample Vendor for Red Teaming as a Service in the Gartner Hype Cycle for XaaS, 2026, published 7 July 2026. Five…
The two DORA testing programs
Having the right security testing capabilities is not enough. Most firms building a DORA-aligned program are covering the right pillars at the wrong intervals, and that…
The attack your training prepared them for doesn’t exist
I’ve delivered more security awareness sessions than I can count. I’m also a social engineer, which means I’ve been the person those sessions are trying to…