logo

Critical Veeam RCE bug now used in Frag ransomware attacks

ID: 96c88b09-9f60-5c8a-ab72-7a116ea71658

STIX ID: report--96c88b09-9f60-5c8a-ab72-7a116ea71658

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-11-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical unauthenticated deserialization RCE in Veeam Backup & Replication (CVE-2024-40711) has been actively exploited in the wild—initially by Akira and Fog ransomware operators and more recently by a cluster deploying 'Frag' ransomware—often combined with stolen VPN gateway credentials to create administrative accounts on unpatched, internet-exposed VBR servers; coordinated disclosure and delayed PoC release were used to allow patching, but exploitation continued and poses high risk given Veeam's widespread use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.