Threat Intelligence

Zyxel Switch Flaw Actively Exploited; Veeam Backup Bug Also Under Attack

The Hacker News · 22 Sept 2026
Key Takeaway Check whether your business uses Zyxel GS1900 switches or Veeam backup agents, and apply the available vendor patches immediately rather than waiting for a scheduled update cycle.

The US Cybersecurity and Infrastructure Security Agency has added a vulnerability affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities catalog, confirming it is being actively used in attacks. The flaw, CVE-2026-7273, is a stack based buffer overflow in the switch's web management interface that lets an unauthenticated attacker on the local network run operating system commands by sending a specially crafted web request. Zyxel released a fix in June 2026, and federal agencies have been ordered to patch by September 24, 2026. CISA has not shared details on who is behind the attacks or how many organisations have been affected.

Separately, security firm Arctic Wolf has warned of active exploitation of a privilege escalation flaw in Veeam Agent for Microsoft Windows, tracked as CVE-2026-32996. The bug lies in how the Veeam Endpoint Backup service handles a local communication channel: it caches administrator level session details that are not properly tied to the user who requested them. Because these session identifiers are written to a log file that any standard user can read, an attacker with local access can reuse the identifier to run commands with full SYSTEM privileges, the highest level of access on a Windows machine. A public proof of concept already demonstrates this technique.

Both flaws highlight how attackers are increasingly targeting network hardware and backup software, tools many small businesses rely on but rarely monitor closely for vulnerabilities.

Zyxel Veeam CISA KEV privilege escalation patch management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.