{"cveID":"CVE-2022-26501","vendorProject":"Veeam","product":"Backup & Replication","vulnerabilityName":"Veeam Backup & Replication Remote Code Execution Vulnerability","dateAdded":"2022-12-13","shortDescription":"The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-01-03","knownRansomwareCampaignUse":"Known","notes":"https://www.veeam.com/kb4288;  https://nvd.nist.gov/vuln/detail/CVE-2022-26501","cwes":["CWE-306"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-26501","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This vulnerability is exploited by a remote, unauthenticated attacker to access internal API functions and send malicious code to the Veeam Distribution Service via the default TCP port 9380.\n\nThis vulnerability has been exploited by threat actors associated with the AvosLocker ransomware. Kroll analysts have observed these actors using this vulnerability, alongside CVE-2022-26500, to potentially exfiltrate data and download malicious tools while appearing as legitimate activity to evade detection.","references":["https://www.kroll.com/en/insights/publications/cyber/avoslocker-ransomware-update","https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html","https://www.cloudsek.com/threatintelligence/multiple-rce-vulnerabilities-affecting-veeam-backup-replication","https://www.rapid7.com/db/vulnerabilities/veeam-backup-and-replication-cve-2022-26501/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-26501","technique":"T1036","technique_name_at_mapping":"Masquerading","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited by a remote, unauthenticated attacker to access internal API functions and send malicious code to the Veeam Distribution Service via the default TCP port 9380.\n\nThis vulnerability has been exploited by threat actors associated with the AvosLocker ransomware. Kroll analysts have observed these actors using this vulnerability, alongside CVE-2022-26500, to potentially exfiltrate data and download malicious tools while appearing as legitimate activity to evade detection.","references":["https://www.kroll.com/en/insights/publications/cyber/avoslocker-ransomware-update","https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html","https://www.cloudsek.com/threatintelligence/multiple-rce-vulnerabilities-affecting-veeam-backup-replication","https://www.rapid7.com/db/vulnerabilities/veeam-backup-and-replication-cve-2022-26501/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-26501","technique":"T1048","technique_name_at_mapping":"Exfiltration Over Alternative Protocol","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited by a remote, unauthenticated attacker to access internal API functions and send malicious code to the Veeam Distribution Service via the default TCP port 9380.\n\nThis vulnerability has been exploited by threat actors associated with the AvosLocker ransomware. Kroll analysts have observed these actors using this vulnerability, alongside CVE-2022-26500, to potentially exfiltrate data and download malicious tools while appearing as legitimate activity to evade detection.","references":["https://www.kroll.com/en/insights/publications/cyber/avoslocker-ransomware-update","https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html","https://www.cloudsek.com/threatintelligence/multiple-rce-vulnerabilities-affecting-veeam-backup-replication","https://www.rapid7.com/db/vulnerabilities/veeam-backup-and-replication-cve-2022-26501/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-26501","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited by a remote, unauthenticated attacker to access internal API functions and send malicious code to the Veeam Distribution Service via the default TCP port 9380.\n\nThis vulnerability has been exploited by threat actors associated with the AvosLocker ransomware. Kroll analysts have observed these actors using this vulnerability, alongside CVE-2022-26500, to potentially exfiltrate data and download malicious tools while appearing as legitimate activity to evade detection.","references":["https://www.kroll.com/en/insights/publications/cyber/avoslocker-ransomware-update","https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html","https://www.cloudsek.com/threatintelligence/multiple-rce-vulnerabilities-affecting-veeam-backup-replication","https://www.rapid7.com/db/vulnerabilities/veeam-backup-and-replication-cve-2022-26501/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1036","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Masquerading","name_at_mapping":"Masquerading","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":40,"has_detection_strategy":true},{"id":"T1048","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exfiltration Over Alternative Protocol","name_at_mapping":"Exfiltration Over Alternative Protocol","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":12,"has_detection_strategy":true},{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}