[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHnZdj8WTlB5t4aNEEDs3FA9sw2BDK8G66YKUKiX0Buc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"774f5f3a-bb7b-4b18-b89e-b65de2293cc6","unpatched-zyxel-and-veeam-flaws-actively-exploited-for-command-and-system-access","5b023265-84c4-493c-bc10-99c5da54bedf","Unpatched Zyxel and Veeam Flaws Actively Exploited for Command and SYSTEM Access","Attackers are actively exploiting a stack-based buffer overflow in Zyxel GS1900 switches that allows unauthenticated LAN-based attackers to execute OS commands, and a local privilege escalation flaw in Veeam Agent for Windows that grants SYSTEM-level control. Both vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog, signaling confirmed, real-world abuse. The Zyxel flaw is particularly dangerous because it requires no authentication, meaning any device on the local network segment can serve as an attack origin. Together, these flaws highlight the compounding risk of unpatched network infrastructure and endpoint backup agents — two asset classes that are often deprioritized in patch cycles. Delays in applying available patches directly translate into open windows for attackers to gain deep, persistent control.","**Immediate actions:**\n- Apply the latest vendor-supplied patches for Zyxel GS1900 switches and Veeam Agent for Windows without delay.\n- Add both CVEs to your internal vulnerability tracking system and verify patch status across all affected assets within 24–48 hours.\n- Restrict LAN-side access to Zyxel management interfaces using firewall rules or ACLs to limit exposure until patching is complete.\n\n**Long-term improvements:**\n- Maintain a continuously updated asset inventory that includes network appliances, switches, and backup agents to ensure no device is overlooked during patch cycles.\n- Establish an emergency patching SLA (e.g., 24–72 hours) triggered automatically when CISA adds a vulnerability to the KEV catalog.\n- Enforce least-privilege principles for local accounts on Windows endpoints to limit the blast radius of local privilege escalation exploits.\n\n**Detection measures:**\n- Monitor network switches and backup agent logs for anomalous command execution, privilege changes, or unexpected process spawning.\n- Deploy network-based intrusion detection rules targeting exploit patterns associated with CVE-2026-7273 and CVE-2026-32996.\n- Integrate threat intelligence feeds (e.g., CISA KEV catalog) into your vulnerability scanner to automatically flag actively exploited CVEs for priority remediation.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 12: Network Infrastructure Management","NIST SP 800-40: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST AC-6: Least Privilege","NIST SC-7: Boundary Protection","CISA KEV Catalog Binding Operational Directive 22-01","ITIL Change Management: Emergency Change Procedures","NIST CM-8: Information System Component Inventory","published","2026-09-22T08:21:38.809472+00:00","2026-09-22T08:21:38.732+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fzyxel-and-veeam-flaws-under-active.html","zyxel-and-veeam-flaws-under-active-exploitation-with-command-and-system-access-b6c97d","Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]