September 27, 2026

Zyxel Switches and Veeam Agent Are Being Exploited Now

Zyxel Switches and Veeam Agent Are Being Exploited Now

Two patches your team needs to apply this week

If your office runs Zyxel GS1900 series switches or uses Veeam Agent for Windows to back up endpoints, stop and read this. Both products have confirmed, actively exploited vulnerabilities right now. One lets an unauthenticated attacker on your local network run arbitrary OS commands on your switch. The other lets anyone with a standard Windows account escalate to full SYSTEM control on that machine.

What the Zyxel flaw actually does

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series switch firmware, with a CVSS score of 8.8. A LAN-based, unauthenticated attacker sends a crafted HTTP request and can execute arbitrary OS commands on the device. No login required.

According to reporting from The Hacker News, a suspected Chinese-speaking threat actor has been exploiting this since August 17, 2026. By the time CISA added it to the Known Exploited Vulnerabilities catalog on September 22, 2026, the attacker had already hit 996 Zyxel switches across 48 countries. The exploit retrieved device configurations, hashed root credentials, and networking information off the switches.

Zyxel patched this in June 2026. Affected GS1900 models include the GS1900-8, 8HP, 10HP, 16, 24, 24E, 24EP, 24HPv2, 48, and 48HPv2, each with a corresponding 2.90(.x.2)C0 fixed firmware release. Log into your switch management interface, check the firmware version, and update if you’re on the .1 build or earlier.

The Veeam Agent flaw is a different kind of problem

CVE-2026-32996 is a local privilege escalation in Veeam Agent for Microsoft Windows, CVSS score 7.3. The flaw is in how the Veeam Endpoint Backup service handles elevated client sessions over a local named pipe. The service caches an elevated administrator session tied to a client-controlled session UID, but that UID isn’t bound to the requesting user or connection.

Elevated session UIDs get written to a log file at C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log, and standard users can read that file. Any local user can grab a valid UID from the log and run commands as SYSTEM. A public proof-of-concept on GitHub already demonstrates this. Arctic Wolf confirmed active exploitation on September 22, 2026. Patch immediately through Intune, SCCM, or your RMM platform.

The broader pattern worth paying attention to

Both vulnerabilities landed on CISA’s KEV catalog, a reliable signal that exploitation is real and widespread. Network hardware like managed switches often gets ignored in patching cycles because it doesn’t show up in Windows Update. If your team doesn’t have a documented process for firmware updates on switches, firewalls, and access points, that gap is worth closing.

Patch the Zyxel firmware, update Veeam Agent, and confirm both through your change log. If you want help building a patching process that covers network hardware and not just Windows machines, Exine offers managed IT and cybersecurity for businesses across NJ and NYC.

FAQ

Is the Zyxel GS1900 vulnerability exploitable from the internet?

No. CVE-2026-7273 requires LAN-based access. Once someone is inside your network, they can exploit it without any credentials. Patch the firmware and segment your management interfaces regardless.

Can the Veeam Agent flaw be exploited remotely?

No. CVE-2026-32996 requires local access to the machine. It’s still serious because it turns a limited user account into full SYSTEM access, which is enough to install malware, disable security tools, or move laterally.

How do I know if my Veeam Agent version is vulnerable?

Check the version installed on your Windows endpoints against Veeam’s official advisory for CVE-2026-32996 at the NVD entry for CVE-2026-32996. If you manage endpoints through Intune or an RMM platform, you can query installed software versions across your fleet from a central dashboard.

Tomasz Sobolewski, founder of Exine LLC
About the author
Tomasz Sobolewski
Founder of Exine LLC. Hands-on IT, cybersecurity and backup for growing New Jersey businesses, with 15+ years in the field. The kind of support that knows your systems and picks up the phone.