Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
What it means
CISA ha aggiunto CVE-2026-7273, un buffer overflow stack in Zyxel GS1900 series switches, al KEV catalog, segnalando attacco attivo. La vulnerabilità permette esecuzione di comandi OS tramite HTTP. Le versioni interessate sono state fissate. Un'altra vulnerabilità, CVE-2026-32996, è sfruttata attivamente per escalation di privilegi in Veeam Agent for Windows.
Why it matters
Le PMI italiane che utilizzano dispositivi Zyxel o Veeam Agent per Windows sono a rischio di accesso non autorizzato e compromissione dei sistemi. L'attacco attivo richiede immediata mitigazione per evitare danni operativi e di dati.
Recommended actions
- Applicare le patch disponibili per Zyxel GS1900 series switches
- Verificare le versioni di Veeam Agent for Windows e applicare le patch
- Ridurre l'esposizione di dispositivi Zyxel in rete interna
- Implementare controlli di accesso per limitare l'accesso a servizi Veeam
- Monitorare i log di Veeam Endpoint Backup per UID anomali
- Eseguire audit di accesso e controllo di privilegi
Potential operational benefits
- Riduzione della superficie esposta a vulnerabilità note
- Prevenzione di accessi non autorizzati e escalation di privilegi
- Miglioramento del rilevamento e risposta agli attacchi
- Aumento della conformità alle normative di sicurezza
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating
- Source
- The Hacker News
- Publishing entity
- The Hacker News
- Entity type
- editorial osint
- Area
- Global
- Original language
- en · translation in preparation
- Publication
- 22/09/2026 07:31
- MITRE ATT&CK
- T1059.001, T1562.001, T1078
- CVE
- CVE-2026-7273
Affected products and versions
The collector will check NVD and the available official vendor advisories.