{"id":3047,"date":"2026-09-22T08:51:43","date_gmt":"2026-09-22T08:51:43","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3047"},"modified":"2026-09-22T08:51:43","modified_gmt":"2026-09-22T08:51:43","slug":"zyxel-and-veeam-flaws-under-active-exploitation-with-command-and-system-access","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3047","title":{"rendered":"Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 22, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Endpoint Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjj9eouOxeSvnYBzl5A8tWvEQ4w_CCx94YcFmpBAXXqHWNqvFBWj4vOgeZdHYAf0MU-chY63biCpHDnzRC0pwR7s3pTdQAWwPAVI-olRZuBwG0ilgAxnIY_1KofE3cpuA8lKOE01U26EFHYE_nLrXYXOWl47G1KaoFTZ5UOO81Cw0Kb20pFSfAc1b9i9E_K\/s1700-nu-rw-lo-l85-e365\/veeam.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/21\/cisa-adds-one-known-exploited-vulnerability-catalog\" target=\"_blank\">added<\/a> a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, citing evidence of active exploitation.<\/p>\n<p>The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution.<\/p>\n<p>\u00abA stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request,\u00bb Zyxel <a href=\"https:\/\/www.zyxel.com\/global\/en\/support\/security-advisories\/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026\" target=\"_blank\">said<\/a> in an advisory released in June 2026. <\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The issue has been addressed in the following versions &#8211;<\/p>\n<p><a name=\"more\"\/><\/p>\n<ul>\n<li>GS1900-8 2.90(AAHH.1)C0 and earlier &#8211; Fixed in 2.90(AAHH.2)C0<\/li>\n<li>GS1900-8HP 2.90(AAHI.1)C0 and earlier &#8211; Fixed in 2.90(AAHI.2)C0<\/li>\n<li>GS1900-10HP 2.90(AAZI.1)C0 and earlier &#8211; Fixed in 2.90(AAZI.2)C0<\/li>\n<li>GS1900-16 2.90(AAHJ.1)C0 and earlier &#8211; Fixed in 2.90(AAHJ.2)C0<\/li>\n<li>GS1900-24 2.90(AAHL.1)C0 and earlier &#8211; Fixed in 2.90(AAHL.2)C0<\/li>\n<li>GS1900-24E 2.90(AAHK.1)C0 and earlier &#8211; Fixed in 2.90(AAHK.2)C0<\/li>\n<li>GS1900-24EP 2.90(ABTO.1)C0 and earlier &#8211; Fixed in 2.90(ABTO.2)C0<\/li>\n<li>GS1900-24HPv2 2.90(ABTP.1)C0 and earlier &#8211; Fixed in 2.90(ABTP.2)C0<\/li>\n<li>GS1900-48 2.90(AAHN.1)C0 and earlier &#8211; Fixed in 2.90(AAHN.2)C0<\/li>\n<li>GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier &#8211; Fixed in 2.90(ABTQ.2)C0<\/li>\n<\/ul>\n<p>CISA hasn&#8217;t disclosed who was behind the exploitation efforts, when they started, how many organizations have been targeted, how many of them have been successful, and what attackers did once inside the vulnerable service.<\/p>\n<p>Zyxel credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS for discovering and reporting the vulnerability. As of writing, the company has yet to revise the alert to confirm active exploitation.<\/p>\n<p>In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by September 24, 2026, for optimal protection.<\/p>\n<h3>Active Exploitation of Veeam Agent for Windows Flaw<\/h3>\n<p>This disclosure comes as Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/update-active-exploitation-cve-2026-32996-of-veeam-agent\/\" target=\"_blank\">warned<\/a> of active exploitation of CVE-2026-32996 (CVSS score: 7.3), a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows that allows an attacker with local access to obtain SYSTEM-level control of affected endpoints.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe issue stems from the Veeam Endpoint Backup service&#8217;s handling of elevated client sessions over the local gRPC named pipe \\\\.\\pipe\\Veeam\\VAW\\ServiceConnectionPipe,\u00bb the company said. \u00abThe service caches an elevated administrator principal against a client-controlled session UID that is not bound to the requesting user or connection.\u00bb<\/p>\n<p>\u00abBecause elevated session UIDs are written to C:\\ProgramData\\Veeam\\Endpoint\\Svc.VeeamEndpointBackup.log, which standard users can read, an attacker can obtain a valid UID and abuse it to execute commands as SYSTEM. The public GitHub PoC demonstrates this by running whoami and writing the output to a file.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 22, 2026Vulnerability \/ Endpoint Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3048,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,64,1223,65,11,1045,647,3492],"class_list":["post-3047","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-active","tag-command","tag-exploitation","tag-flaws","tag-system","tag-veeam","tag-zyxel"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3047"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3047\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3048"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}