Active attacks on Zyxel and Veeam flaws expose core corporate systems
Attackers are exploiting security weaknesses in Zyxel GS1900 switches and Veeam Agent for Windows, using one flaw to run operating system commands from inside local networks and another to gain SYSTEM‑level control on Windows machines. Organizations that rely on these products for connectivity and backups face fresh exposure if they haven’t applied fixes.
Two widely deployed pieces of IT infrastructure are under live attack, with new vulnerabilities in Zyxel networking gear and Veeam backup software opening up serious paths into corporate systems.
According to security reporting, attackers are targeting flaws in Zyxel GS1900 series switches and in Veeam Agent for Windows. These aren’t lab‑only bugs: exploitation is already taking place in real‑world environments.
In Zyxel’s case, the vulnerability allows operating system commands to be executed from the local area network without any authentication. GS1900 switches are often used in office networks to link servers, workstations and other devices. If an attacker with access to the LAN can run OS‑level commands on these switches, they can tamper with configurations, reroute or monitor traffic, or use the device to move deeper into the network.
The Veeam Agent for Windows flaw is different but comparably dangerous. It lets a local attacker obtain SYSTEM privileges, the highest level of control on a Windows system. Because Veeam tools manage backups and recovery, a compromise at that level risks giving an attacker broad access to stored data and the ability to interfere with backup integrity.
For IT and security teams, this shifts normally background infrastructure into the foreground of risk. Switches that were treated as mostly static hardware and backup agents that quietly ran in the background now require urgent checks for vulnerable versions and rapid patching.
The immediate priority is to follow the technical guidance in the public write‑ups on these flaws, including vendor advisories linked by security news outlets such as The Hacker News. Over the coming days, the key signals will be how quickly organizations deploy fixes and whether these exploits appear in mainstream crimeware and ransomware operations, turning targeted intrusions into broader campaigns.
Sources
- OSINT