Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zyxel and Veeam Vulnerabilities Under Active Exploit

Zyxel and Veeam Vulnerabilities Under Active Exploit

Posted on September 22, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a significant vulnerability affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog. This decision follows evidence that the flaw, although now patched, is being actively exploited. Identified as CVE-2026-7273 with a CVSS score of 8.8, the issue involves a stack-based buffer overflow that permits arbitrary operating system command execution.

Zyxel Vulnerability Details

The Zyxel GS1900 series switches are susceptible to a stack-based buffer overflow vulnerability within their CGI program. This flaw allows unauthenticated attackers on the LAN to potentially execute operating system commands through a specially crafted HTTP request. Zyxel addressed this issue by releasing patches for various models in June 2026.

The affected switch firmware versions and their respective fixes include GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2. Despite these updates, CISA has not disclosed specifics regarding the entities behind the exploitation, the timeline of the attacks, or the success rate of these malicious efforts.

Security Measures and Acknowledgements

In response to the ongoing exploitation, Federal Civilian Executive Branch (FCEB) agencies have been mandated to implement the necessary patches by September 24, 2026. Zyxel credited the discovery and reporting of the vulnerability to Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS. However, Zyxel’s official advisory has yet to confirm the active exploitation status.

Veeam Agent for Windows Exploitation

Simultaneously, Arctic Wolf has flagged an active exploitation of CVE-2026-32996, a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows. This flaw, rated with a CVSS score of 7.3, enables attackers with local access to gain SYSTEM-level control over affected endpoints.

The vulnerability originates from the Veeam Endpoint Backup service’s mishandling of elevated client sessions via the local gRPC named pipe. This issue allows attackers to retrieve and exploit session UIDs logged in a location accessible to standard users, enabling them to execute commands with elevated privileges. A public proof of concept on GitHub demonstrates this exploit by running the ‘whoami’ command and logging the output.

Both the Zyxel and Veeam vulnerabilities highlight the critical need for prompt patching and vigilant network monitoring to safeguard against potential exploitation. Organizations are encouraged to stay updated with security advisories and patches to protect their systems from these threats.

The Hacker News Tags:buffer overflow, CISA, CVE-2026-32996, CVE-2026-7273, Cybersecurity, endpoint security, Exploitation, local privilege escalation, network security, SYSTEM access, Veeam, Vulnerabilities, Zyxel

Post navigation

Previous Post: Japan Dismantles North Korean Laptop Farm Amid Global Cyber Scheme
Next Post: WordPress Addresses Critical Security Flaw ‘Click2Shell’

Related Posts

Lotus Wiper Threatens Venezuela’s Energy Sector Lotus Wiper Threatens Venezuela’s Energy Sector The Hacker News
Langflow Security Flaw Enables Unauthenticated Access Langflow Security Flaw Enables Unauthenticated Access The Hacker News
AI’s Role in Evolving Cybersecurity Validation AI’s Role in Evolving Cybersecurity Validation The Hacker News
QuickFox VPN Targeted in Supply Chain Attack Exposing Users QuickFox VPN Targeted in Supply Chain Attack Exposing Users The Hacker News
CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited The Hacker News
Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & More Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights
  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights
  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark