Ransomware

Recent Veeam Vulnerability Exploited in Ransomware Attacks

Sophos warns of ransomware operators exploiting a critical code execution vulnerability in Veeam Backup & Replication.

Sophos warns of ransomware operators exploiting a critical code execution vulnerability in Veeam Backup & Replication.

Ransomware operators are exploiting a critical-severity vulnerability in Veeam Backup & Replication to create rogue accounts and deploy malware, Sophos warns.

The issue, tracked as CVE-2024-40711 (CVSS score of 9.8), can be exploited remotely, without authentication, for arbitrary code execution, and was patched in early September with the release of Veeam Backup & Replication version 12.2 (build 12.2.0.334).

While neither Veeam, nor Code White, which was credited with reporting the bug, have shared technical details, attack surface management firm WatchTowr performed an in-depth analysis of the patches to better understand the vulnerability.

CVE-2024-40711 consisted of two issues: a deserialization flaw and an improper authorization bug. Veeam fixed the improper authorization in build 12.1.2.172 of the product, which prevented anonymous exploitation, and included patches for the deserialization bug in build 12.2.0.334, WatchTowr revealed.

Given the severity of the security defect, the security firm refrained from releasing a proof-of-concept (PoC) exploit, noting “we’re a little worried by just how valuable this bug is to malware operators.” Sophos’ fresh warning validates those fears.

“Sophos X-Ops MDR and Incident Response are tracking a series of attacks in the past month leveraging compromised credentials and a known vulnerability in Veeam (CVE-2024-40711) to create an account and attempt to deploy ransomware,” Sophos noted in a Thursday post on Mastodon.

Advertisement. Scroll to continue reading.

The cybersecurity firm says it has observed attackers deploying the Fog and Akira ransomware and that indicators in four incidents overlap with previously observed attacks attributed to these ransomware groups.

According to Sophos, the threat actors used compromised VPN gateways that lacked multi-factor authentication protections for initial access. In some cases, the VPNs were running unsupported software iterations.

“Each time, the attackers exploited Veeam on the URI /trigger on port 8000, triggering the Veeam.Backup.MountService.exe to spawn net.exe. The exploit creates a local account, ‘point’, adding it to the local Administrators and Remote Desktop Users groups,” Sophos said.

Following the successful creation of the account, the Fog ransomware operators deployed malware to an unprotected Hyper-V server, and then exfiltrated data using the Rclone utility.

Related: Okta Tells Users to Check for Potential Exploitation of Newly Patched Vulnerability

Related: Apple Patches Vision Pro Vulnerability to Prevent GAZEploit Attacks

Related: LiteSpeed Cache Plugin Vulnerability Exposes Millions of WordPress Sites to Attacks

Related: The Imperative for Modern Security: Risk-Based Vulnerability Management

Related Content

Ransomware

Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Vulnerabilities

The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.

Cybercrime

Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation.

Vulnerabilities

Oracle has released mitigations for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks.

Vulnerabilities

Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.

Vulnerabilities

The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. 

Vulnerabilities

The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version