[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6P7FH1IHpYUwDXBjt_ka9pkNk2cKHJ4qzFSov30D7fo":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"5b023265-84c4-493c-bc10-99c5da54bedf","Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access","zyxel-and-veeam-flaws-under-active-exploitation-with-command-and-system-access-b6c97d","The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating","CISA has added a vulnerability in Zyxel GS1900 series switches (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog, noting active exploitation. This stack-based buffer overflow flaw allows unauthenticated LAN-based attackers to execute OS commands. Additionally, Arctic Wolf reported active exploitation of a local privilege escalation vulnerability in Veeam Agent for Windows (CVE-2026-32996), allowing attackers with local access to gain SYSTEM-level control.","CISA adds Zyxel and Veeam flaws to KEV catalog due to active exploitation.","Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Ravie LakshmananSep 22, 2026Vulnerability \u002F Endpoint Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution. \"A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request,\" Zyxel said in an advisory released in June 2026. The issue has been addressed in the following versions - GS1900-8 2.90(AAHH.1)C0 and earlier - Fixed in 2.90(AAHH.2)C0 GS1900-8HP 2.90(AAHI.1)C0 and earlier - Fixed in 2.90(AAHI.2)C0 GS1900-10HP 2.90(AAZI.1)C0 and earlier - Fixed in 2.90(AAZI.2)C0 GS1900-16 2.90(AAHJ.1)C0 and earlier - Fixed in 2.90(AAHJ.2)C0 GS1900-24 2.90(AAHL.1)C0 and earlier - Fixed in 2.90(AAHL.2)C0 GS1900-24E 2.90(AAHK.1)C0 and earlier - Fixed in 2.90(AAHK.2)C0 GS1900-24EP 2.90(ABTO.1)C0 and earlier - Fixed in 2.90(ABTO.2)C0 GS1900-24HPv2 2.90(ABTP.1)C0 and earlier - Fixed in 2.90(ABTP.2)C0 GS1900-48 2.90(AAHN.1)C0 and earlier - Fixed in 2.90(AAHN.2)C0 GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier - Fixed in 2.90(ABTQ.2)C0 CISA hasn't disclosed who was behind the exploitation efforts, when they started, how many organizations have been targeted, how many of them have been successful, and what attackers did once inside the vulnerable service. Zyxel credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS for discovering and reporting the vulnerability. As of writing, the company has yet to revise the alert to confirm active exploitation. In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by September 24, 2026, for optimal protection. Active Exploitation of Veeam Agent for Windows Flaw This disclosure comes as Arctic Wolf warned of active exploitation of CVE-2026-32996 (CVSS score: 7.3), a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows that allows an attacker with local access to obtain SYSTEM-level control of affected endpoints. \"The issue stems from the Veeam Endpoint Backup service's handling of elevated client sessions over the local gRPC named pipe \\\\.\\pipe\\Veeam\\VAW\\ServiceConnectionPipe,\" the company said. \"The service caches an elevated administrator principal against a client-controlled session UID that is not bound to the requesting user or connection.\" \"Because elevated session UIDs are written to C:\\ProgramData\\Veeam\\Endpoint\\Svc.VeeamEndpointBackup.log, which standard users can read, an attacker can obtain a valid UID and abuse it to execute commands as SYSTEM. The public GitHub PoC demonstrates this by running whoami and writing the output to a file.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  endpoint security, network security, Vulnerability, Windows Security ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fzyxel-and-veeam-flaws-under-active.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjj9eouOxeSvnYBzl5A8tWvEQ4w_CCx94YcFmpBAXXqHWNqvFBWj4vOgeZdHYAf0MU-chY63biCpHDnzRC0pwR7s3pTdQAWwPAVI-olRZuBwG0ilgAxnIY_1KofE3cpuA8lKOE01U26EFHYE_nLrXYXOWl47G1KaoFTZ5UOO81Cw0Kb20pFSfAc1b9i9E_K\u002Fs1600\u002Fveeam.jpg","2026-09-22T05:31:59+00:00","2026-09-22T08:00:29.46545+00:00",9,[18,21,24,26,28,30],{"name":19,"type":20},"GS1900 series switches","product",{"name":22,"type":23},"Zyxel","vendor",{"name":25,"type":20},"Veeam Agent for Microsoft Windows",{"name":27,"type":23},"Veeam",{"name":29,"type":20},"Veeam Endpoint Backup service",{"name":31,"type":23},"Arctic Wolf","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43,45],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":32,"icon":34,"name":35,"slug":36},{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55],{"type":52,"value":53,"context":54},"cve","CVE-2026-7273","Zyxel GS1900 series switch stack-based buffer overflow vulnerability",{"type":52,"value":56,"context":57},"CVE-2026-32996","Veeam Agent for Windows local privilege escalation vulnerability"]