logo

Ransomware Gangs Exploit Critical Vulnerability In Veeam

ID: fdc6f184-216e-5844-a0b2-19187233f26f

STIX ID: report--fdc6f184-216e-5844-a0b2-19187233f26f

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2024-10-17

Date Updated: 2026-07-20

...
...

Veeam Backup & Replication contains a critical unauthenticated remote code execution vulnerability (CVE-2024-40711, CVSS 9.8) that has been exploited in the wild to deploy Akira and Fog ransomware and exfiltrate data; thousands of internet-exposed instances were identified, attackers leveraged exposed VPN gateways and port 8000 to trigger Veeam processes, create privileged local accounts (e.g., “point”), and use tools like rclone, while Veeam released patches in early September 2024 and organizations are urged to patch, restrict exposure, enforce MFA, and monitor for indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.