Multiple ransomware groups have been exploiting a critical authentication bypass in Veeam Backup & Replication, identified as CVE-2024-40711, to gain access to backup infrastructure and deploy ransomware. Reporting tied the activity to at least one newly observed ransomware operation, with attackers abusing the flaw to compromise internet-exposed Veeam servers, move deeper into victim environments, and target backup systems that are often central to recovery efforts.
The vulnerability affects domain-joined Veeam Backup & Replication servers, and successful exploitation can allow remote code execution under certain conditions. Security reporting said the bug was being used in real-world intrusions shortly after disclosure, underscoring the risk to organizations that rely on Veeam for business continuity. Defenders were urged to patch affected systems, restrict external exposure of backup management interfaces, and monitor Veeam infrastructure for signs of unauthorized access or ransomware deployment.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting indicated that exploitation of CVE-2024-40711 was not limited to a single actor and involved multiple ransomware groups. This marked an escalation from isolated activity to broader criminal adoption of the vulnerability.
Researchers reported that a newly observed ransomware group, Frag, was exploiting CVE-2024-40711 in attacks. This added attribution detail to the broader wave of ransomware activity targeting the Veeam flaw.
Threat actors started exploiting the Veeam Backup & Replication vulnerability CVE-2024-40711 to gain access to victim environments. Reporting in July indicated the bug was being used in real-world ransomware intrusions.
Veeam disclosed and released fixes for CVE-2024-40711, a critical remote code execution vulnerability affecting Backup & Replication. The flaw later became the focus of ransomware exploitation activity.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.