Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The Hacker News by The Hacker News
September 22, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 22, 2026Vulnerability / Endpoint Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution.

“A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request,” Zyxel said in an advisory released in June 2026. 

The issue has been addressed in the following versions –

  • GS1900-8 2.90(AAHH.1)C0 and earlier – Fixed in 2.90(AAHH.2)C0
  • GS1900-8HP 2.90(AAHI.1)C0 and earlier – Fixed in 2.90(AAHI.2)C0
  • GS1900-10HP 2.90(AAZI.1)C0 and earlier – Fixed in 2.90(AAZI.2)C0
  • GS1900-16 2.90(AAHJ.1)C0 and earlier – Fixed in 2.90(AAHJ.2)C0
  • GS1900-24 2.90(AAHL.1)C0 and earlier – Fixed in 2.90(AAHL.2)C0
  • GS1900-24E 2.90(AAHK.1)C0 and earlier – Fixed in 2.90(AAHK.2)C0
  • GS1900-24EP 2.90(ABTO.1)C0 and earlier – Fixed in 2.90(ABTO.2)C0
  • GS1900-24HPv2 2.90(ABTP.1)C0 and earlier – Fixed in 2.90(ABTP.2)C0
  • GS1900-48 2.90(AAHN.1)C0 and earlier – Fixed in 2.90(AAHN.2)C0
  • GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier – Fixed in 2.90(ABTQ.2)C0

The addition follows a report from GreyNoise about a suspected Chinese-speaking malicious cyber actor that has weaponized the flaw since August 17, 2026, successfully exploiting and exfiltrating data from 996 Zyxel switches across 48 countries, including Italy, the U.S., Taiwan, France, and South Korea.

The attacker is said to have leveraged the exploit to execute the Trivial File Transfer Protocol (TFTP) tool to retrieve and execute a custom collector script. The transmitted data relates to configurations, hashed root-level credentials, and networking information.

“The exploit code was contained within a Python script which was heavily obfuscated by the commercial obfuscation tool PyArmor,” GreyNoise said. “While the script explicitly targets firmware versions 2.10-2.90 of the GS1900-24, it does provide command line options (e.g., libc base address, global offsets), for targeting other firmware in scope for the vulnerability.”

It’s worth noting that the threat actor is either the same or shares overlaps with a cluster that Acronis disclosed last week, abusing a recently disclosed security vulnerability in Gitea (CVE-2026-60004) to break into internet-facing instances. The cybersecurity company is tracking the activity under the name Red Heron.

Besides, Gitea and Zyxel flaws, the adversary has been observed exploiting flaws in UniFi OS (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910), Flowise (CVE-2026-56271), WordPress (CVE-2026-63030 and CVE-2026-60137), Linux kernel (CVE-2022-0847), Nuclio (CVE-2026-79756), SENAITE LIMS (CVE-2026-54569), Proxmox VE (CVE-2023-54391), and an unspecified flaw Palo Alto Networks PAN-OS GlobalProtect portals.

Zyxel credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS for discovering and reporting the vulnerability. As of writing, the company has yet to revise the alert to confirm active exploitation.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by September 24, 2026, for optimal protection.

Active Exploitation of Veeam Agent for Windows Flaw

This disclosure comes as Arctic Wolf warned of active exploitation of CVE-2026-32996 (CVSS score: 7.3), a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows that allows an attacker with local access to obtain SYSTEM-level control of affected endpoints.

“The issue stems from the Veeam Endpoint Backup service’s handling of elevated client sessions over the local gRPC named pipe \.pipeVeeamVAWServiceConnectionPipe,” the company said. “The service caches an elevated administrator principal against a client-controlled session UID that is not bound to the requesting user or connection.”

“Because elevated session UIDs are written to C:ProgramDataVeeamEndpointSvc.VeeamEndpointBackup.log, which standard users can read, an attacker can obtain a valid UID and abuse it to execute commands as SYSTEM. The public GitHub PoC demonstrates this by running whoami and writing the output to a file.”



Source link

The Hacker News

The Hacker News

Next Post

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

Recommended.

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

September 1, 2026
Network Security Market is expected to generate a revenue of USD 118.63 Billion by 2032, Globally, at 12.8% CAGR: Verified Market Research®

Network Security Market is expected to generate a revenue of USD 118.63 Billion by 2032, Globally, at 12.8% CAGR: Verified Market Research®

March 24, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio