We would like to bring your attention to the following unauthenticated remote code execution vulnerability within Veeam Backup & Replication. This issue is being tracked as CVE-2022-26500 & CVE-2022-26501 and has been given the CVSS v3 score of 9.8.
At this time we are unaware of any proof of concept attacks or exploits for this issue being available in the wild, we will continue to monitor the situation around this.
Am I affected?
Versions of Veeam prior to the following versions are known to be vulnerable (including the unsupported version 9.5):
-
11a (build 11.0.1.1261 P20220302)
-
10a (build 10.0.1.4854 P20220304)
Remediation
Apply the patches provided by Veeam to your Veeam Backup and Replication Server:
References
-
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26500
-
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26501
CovertSwarm named a Sample Vendor for Agentic Red Teaming in the Gartner® Emerging Tech Impact Radar: Preemptive Cybersecurity
The question for security leaders is who’s in charge of the agents that test their defenses. We think it should be ethical hackers. That’s how we’re…
Security by obscurity is dead.
On June 18, 2026, an OpenAI agent got into the Medicare statistics reporting service portal run by Services Australia. ABC News describes it as a legacy…
The growing impact of nation-state cyber-attacks on businesses
Nation-state cyber threats no longer stop at government and defense. Here’s what makes these attackers different, and what it actually takes to raise the bar against…