# Zyxel and Veeam flaws under active attack put corporate networks and backups at risk

*Tuesday, September 22, 2026 at 6:11 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-22T06:11:28.140Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18519.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are actively exploiting security holes in Zyxel GS1900 switches and Veeam Agent for Windows that can hand over command execution and SYSTEM‑level control. For companies that rely on these devices and backup tools, the bugs turn routine network gear and last‑line data protection into potential entry points.

Two widely used pieces of enterprise infrastructure—an access‑layer network switch and a backup agent—are now confirmed to be under live attack, giving intruders a shortcut into corporate environments that thought they were simply doing basic IT maintenance.

Security researchers report that attackers are exploiting a vulnerability in Zyxel’s GS1900 series switches that allows operating system commands to be run from the local network without any authentication. In simple terms, someone who can reach the device from inside the LAN can make it run arbitrary commands as if they were an administrator. At the same time, a flaw in Veeam Agent for Windows is being targeted that can give a local attacker SYSTEM‑level control, the highest privilege level in Windows.

Neither product is exotic. Zyxel GS1900 switches sit in wiring closets and server rooms around the world, quietly connecting office workstations, printers, and servers. Veeam’s backup tools are widely deployed to protect critical data and enable rapid recovery after ransomware or hardware failures. That ubiquity is what turns these vulnerabilities from technical footnotes into concrete risk for hospitals, manufacturers, law firms, and government agencies that may not even know which model of switch is in the rack.

The Zyxel bug is particularly dangerous in flat or poorly segmented networks, where an attacker who has compromised a single workstation or guest device can quickly reach the management interface of core equipment. From there, running OS commands opens the door to installing implants, redirecting traffic, capturing credentials, or disabling security controls. Because the flaw works without a password, existing access policies and strong credentials do little to help if the device itself is exposed from the local side.

The Veeam Agent issue cuts at a different layer of defense. Backup software is supposed to be the last resort after an intrusion or data‑wiping event; here, it is the potential intrusion vector. A local attacker—whether a malicious insider or malware that has landed on a Windows host—can use the flaw to jump from a limited user account to SYSTEM, then turn the machine into a foothold for deeper lateral movement. Once backups are compromised, organizations lose not just data but confidence in their ability to recover safely.

For security teams, the human and operational stakes are immediate. IT staff in midsize organizations may be learning about these issues only when outside consultants or news alerts reach them, even as attackers probe online for exposed devices. Network engineers face the prospect of emergency patching or configuration changes that disrupt business operations, while incident responders must assume that devices they previously treated as low‑risk could already be backdoored.

On a broader level, the active exploitation of these flaws reinforces an uncomfortable reality: attackers no longer need to break directly into hardened servers if they can hijack the unglamorous plumbing of the network or the backup systems meant to save the day. When the switch that routes your traffic and the agent that stores your clean copies are both suspect, the margin for error shrinks sharply.

Organizations now need to track several key signals. Vendors’ release of patches or firmware updates—and whether they are applied quickly—will determine how long the window of easy exploitation stays open. Evidence of these bugs in ransomware incidents or data‑theft campaigns will show whether criminal groups are scaling up their use, and any government advisories naming critical infrastructure sectors at particular risk will hint at whether state‑aligned actors have folded these exploits into their toolkits. For companies, the practical question is whether their inventories and network maps are good enough to even know where every Zyxel switch and Veeam agent lives before someone else finds them first.
