Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
- ID
- 27166
- Status
- summarized
- Published
- 22 Sep 2026, 1:31 PM
- Fetched
- 22 Sep 2026, 4:07 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 22 Sep 2026, 4:08 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
CISA added CVE-2026-7273 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog—a stack-based buffer overflow in Zyxel GS1900 series switches allowing unauthenticated LAN-based attackers to execute OS commands via crafted HTTP requests. Separately, Arctic Wolf reports active exploitation of CVE-2026-32996 (CVSS 7.3), a local privilege escalation flaw in Veeam Agent for Microsoft Windows granting SYSTEM-level access. Patches for Zyxel GS1900 firmware are available across 11 models, with a federal remediation deadline of September 24, 2026.
Why it matters
Zyxel GS1900 switches are common in Malaysian SMB and office network setups—if your team runs any GS1900 model, check firmware versions immediately and apply the 2.90(x.2)C0 patches before the September 24 deadline. If you use Veeam Agent for Windows on any backup server, treat local access as a SYSTEM-escalation risk and patch accordingly.
Discussion angle
How many Malaysian startups and small offices still run unmanaged Zyxel switches on default firmware—quick show of hands on whether anyone has checked their switch firmware version in the last year.