{"cvss":9.8,"datePublished":"2022-12-13","dateUpdated":"2022-12-13","description":"The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.","dueDate":"2023-01-03","id":"CVE-2022-26501","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://www.veeam.com/kb4288;  https://nvd.nist.gov/vuln/detail/CVE-2022-26501","product":"Backup & Replication","requiredAction":"Apply updates per vendor instructions.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Veeam Backup & Replication Remote Code Execution Vulnerability","vendor":"Veeam"}