# Active Zyxel and Veeam Exploits Turn Everyday IT Gear Into Network Takeover Tools

*Tuesday, September 22, 2026 at 6:07 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-22T06:07:10.339Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18510.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting flaws in Zyxel GS1900 switches and Veeam Agent for Windows that allow command execution from inside the network or full control of Windows systems. Routine infrastructure is becoming a launchpad for ransomware, spying and outages.

Two pieces of background IT equipment have moved to the center of current cyber risk. Security researchers say attackers are already exploiting vulnerabilities in Zyxel GS1900 switches and in Veeam Agent for Windows, turning standard infrastructure into direct routes to system compromise.

The Zyxel issue affects GS1900 switches and lets an attacker on the local network run operating system commands on the device without authentication. In practice, anyone who can reach the switch’s management interface from inside the network can start issuing their own instructions. That access can be used to plant persistent malware on the switch, silently redirect or mirror traffic, or use the device as a foothold to move deeper into servers and workstations.

Veeam Agent for Windows, used to back up endpoints and servers, is facing its own serious flaw under active attack. Technical write‑ups describe how a local attacker can exploit the bug to gain SYSTEM‑level privileges — the highest level on a Windows machine. With SYSTEM access, an intruder can disable security software, extract credentials, encrypt data for ransom or quietly siphon off sensitive files.

Most people never see this gear. It sits in wiring closets or runs as background software, which means it often doesn’t get patched with the same urgency as public‑facing servers. That makes these vulnerabilities attractive to attackers looking for reliable ways into supposedly protected environments.

A compromised switch can expose unencrypted traffic and passwords to eavesdropping, or disrupt operations by changing how network segments connect. A hijacked backup agent can turn an organization’s recovery plan into a weakness. Ransomware groups in particular have learned to go after backups first so victims can’t easily restore systems; controlling the agent gives them direct leverage over that process.

The pattern fits a wider shift in attacker focus toward the tools and platforms that organizations trust by default. When core management systems or backup services are subverted, the rest of the network becomes much easier to loot or hold to ransom.

What matters now is how quickly administrators move to contain the risk. That means tracking vendor advisories for affected Zyxel and Veeam versions, applying patches or mitigations, and watching for unusual behavior on switches and Windows hosts tied to backup operations.
