news.mlab.sh
Back to the feed
vulnerability

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

HighCVSS 8.8
Summary

A stack-based buffer overflow vulnerability in Zyxel GS1900 switches is actively being exploited, alongside a separate vulnerability in Veeam Agent for Windows. Both require immediate patching to prevent SYSTEM-level access for attackers. The CISA has added the Zyxel vulnerability to its KEV catalog, and FCEB agencies are under mandate to address the issue by September 24, 2026.

A stack-based buffer overflow vulnerability in Zyxel GS1900 series switches is currently under active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), allows a LAN-based, unauthenticated attacker to execute OS commands via a crafted HTTP request. Zyxel initially identified and reported the issue in June 2026, and the vulnerability has been addressed in several firmware versions, including GS1900-8 2.90(AAHH.1)C0 and earlier, fixed in 2.90(AAHH.2)C0, and GS1900-16 2.90(AAHJ.1)C0 and earlier, fixed in 2.90(AAHJ.2)C0, among others. The CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, and Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by September 24, 2026, for optimal protection.

Meanwhile, Arctic Wolf has warned of active exploitation of CVE-2026-32996 (CVSS score: 7.3), a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows. This issue stems from the Veeam Endpoint Backup service's handling of elevated client sessions over the local gRPC named pipe \.\"Veeam\\"VAW\\"ServiceConnectionPipe. The service caches an elevated administrator principal against a client-controlled session UID that is not bound to the requesting user or connection. Because elevated session UIDs are written to C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log, which standard users can read, an attacker can obtain a valid UID and abuse it to execute commands as SYSTEM. The public GitHub PoC demonstrates this by running whoami and writing the output to a file.

Read the full article at The Hacker News