Ethical Hacking News
A critical vulnerability has been identified in Zyxel network security solutions, with evidence of active exploitation. Additionally, a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows has been discovered, allowing attackers to gain SYSTEM-level control. Organizations are urged to apply the available patches and take proactive measures to mitigate these risks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Two vulnerabilities have been identified in network security solutions Zyxel and Veeam, with CVE-2026-7273 and CVE-2026-32996 being the most notable. The Zyxel vulnerability (CVE-2026-7273) is a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to execute arbitrary operating system commands. The Veeam vulnerability (CVE-2026-32996) is a local privilege escalation vulnerability that allows an attacker with local access to obtain SYSTEM-level control of affected endpoints. CISA and Zyxel have released patches to mitigate these vulnerabilities, with a deadline of September 24, 2026, for Federal Civilian Executive Branch (FCEB) agencies. Organizations are urged to address these security gaps by applying patches and following best practices for network security.
A recent disclosure has highlighted two critical vulnerabilities in prominent network security solutions, Zyxel and Veeam, that are currently under active exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgent need for organizations to address these security gaps.
The first vulnerability, CVE-2026-7273, is a stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switches. This vulnerability, with a CVSS score of 8.8, could potentially allow an unauthenticated attacker to execute arbitrary operating system commands via a crafted HTTP request. According to Zyxel, a LAN-based attacker could exploit this flaw to gain access to the operating system. Fortunately, Zyxel has released patches for affected versions of the GS1900 series switches, which can be applied to mitigate this vulnerability.
The Zyxel vulnerability has been actively exploited, prompting CISA to take notice. As a result, Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by September 24, 2026, for optimal protection. Zyxel has credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from the Institute of Information Engineering (ISCAS) for discovering and reporting the vulnerability.
The second vulnerability, CVE-2026-32996, is a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows. This vulnerability, with a CVSS score of 7.3, allows an attacker with local access to obtain SYSTEM-level control of affected endpoints. Arctic Wolf has warned of active exploitation of this vulnerability, which can be exploited by an attacker with local access to obtain SYSTEM-level control of affected endpoints. The issue stems from the Veeam Endpoint Backup service's handling of elevated client sessions over the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe.
According to Arctic Wolf, an attacker can obtain a valid UID and abuse it to execute commands as SYSTEM. The public GitHub PoC demonstrates this by running whoami and writing the output to a file. Veeam has acknowledged the vulnerability and has released guidance on how to address the issue. However, as of writing, the company has yet to revise the alert to confirm active exploitation.
Both of these vulnerabilities underscore the importance of staying informed about the latest security threats and actively addressing any identified vulnerabilities in your organization's network security solutions. Organizations can take proactive measures to mitigate these risks by applying the available patches and following best practices for network security.
Related Information:
https://www.ethicalhackingnews.com/articles/Critical-Vulnerability-Exposures-Zyxel-and-Veeam-Flaws-Under-Active-Exploitation-ehn.shtml
https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html
https://nvd.nist.gov/vuln/detail/CVE-2026-7273
https://www.cvedetails.com/cve/CVE-2026-7273/
https://nvd.nist.gov/vuln/detail/CVE-2026-32996
https://www.cvedetails.com/cve/CVE-2026-32996/
Published: Tue Sep 22 03:17:25 2026 by llama3.2 3B Q4_K_M