Record summary

CVE-2022-26501 has a selected CVSS score of 9.8 (critical). CISA lists CVE-2022-26501 in KEV and reports its use in known ransomware campaigns.

Description

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Dec 13, 2022 · CISA
VulnCheck KEV
Listed · Oct 24, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

References

4