NewsTradingSentimentEventsCommunityBriefing
Tech

CISA Flags Active Exploitation of Zyxel and Veeam Flaws

By Tech Desk · · 2 min read
A flat-vector illustration of a network switch with multiple ethernet ports and glowing indicator lights.
Illustration: Tradingbird, based on a photo published by The Hacker News

Federal agencies must patch Zyxel switches and Veeam agents by September 24 after CISA confirmed active exploitation of both vulnerabilities.

Key points

  • CISA added a Zyxel GS1900 switch flaw to its KEV catalog due to active exploitation by unauthenticated attackers.
  • Federal agencies must patch the Zyxel vulnerability by September 24, 2026, to mitigate the active threat.
  • A separate Veeam Windows agent flaw is also under active exploitation, allowing local users to gain SYSTEM-level control.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched flaw in Zyxel GS1900 series network switches to its catalog of known exploited vulnerabilities. This move signals that attackers are currently using the weakness to gain control of the devices, a situation that poses an immediate risk to any network relying on these unpatched units.

The vulnerability allows an attacker on the local network to execute arbitrary operating system commands without needing valid login credentials. Because the flaw grants full control over the switch, it can be used to intercept traffic or pivot into deeper parts of a corporate network, making it a critical threat for organizations that have not yet applied the vendor's fix.

Unauthenticated Attackers Gain Control

According to the advisory reported by The Hacker News, the issue is a stack-based buffer overflow in the switch’s firmware. It enables a LAN-based, unauthenticated attacker to send a crafted HTTP request that triggers the overflow, resulting in arbitrary command execution. Zyxel has released updates for various models in the GS1900 series, but the catch is that only those specific versions listed in the advisory contain the fix.

The severity is high, with a CVSS score of 8.8, reflecting the ease of exploitation and the significant impact on system integrity. While the patch is available, many enterprise environments may still be running older firmware versions, leaving them exposed to this active threat.

Federal Deadline for Patching

In response to the active exploitation, CISA has mandated that Federal Civilian Executive Branch agencies apply the necessary fixes by September 24, 2026. This deadline is designed to ensure that government infrastructure is protected from the ongoing attacks, but it also serves as a strong signal to the private sector that this vulnerability is being actively targeted.

The agency did not disclose the identity of the attackers, the scale of the campaign, or the specific objectives of the intrusions. This lack of detail creates uncertainty for defenders, who must assume the worst-case scenario until they can verify their own systems are patched and monitored for signs of compromise.

Veeam Flaw Also Under Attack

Simultaneously, security firm Arctic Wolf has warned of active exploitation of a separate flaw in Veeam Agent for Microsoft Windows. This local privilege escalation vulnerability allows an attacker with basic user access to obtain full SYSTEM-level control of the endpoint. The issue stems from how the Veeam Endpoint Backup service handles elevated client sessions over a local named pipe.

The flaw allows attackers to read log files to find valid session identifiers and then abuse them to execute commands with the highest possible privileges. This combination of a network-level switch compromise and an endpoint-level privilege escalation creates a layered threat that requires immediate attention from IT teams managing both infrastructure and workstations.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories