# Zyxel and Veeam security flaws under active attack give intruders powerful footholds

*Tuesday, September 22, 2026 at 6:13 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-22T06:13:21.925Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18528.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are actively exploiting vulnerabilities in Zyxel GS1900 switches and Veeam Agent for Windows, including a bug that lets commands run on Zyxel devices without authentication from the local network and another that can give a local attacker SYSTEM‑level control on Windows.

Two widely used IT products—Zyxel GS1900 switches and Veeam Agent for Windows—are facing active exploitation of serious security flaws, putting many organizations’ basic network and backup functions at risk.

According to security reporting, the vulnerability in Zyxel’s GS1900 series allows operating system commands to be executed on the switch from the local network without any authentication. In practice, that means anyone with access to the LAN—whether through a compromised device or another foothold—can send commands to the switch and potentially take it over.

Veeam Agent for Windows, a backup tool used to protect systems running Microsoft’s operating system, has a separate weakness that can grant a local attacker SYSTEM‑level control. SYSTEM is the highest‑privileged account on Windows, so gaining it lets an intruder bypass most protections and make deep changes to the machine.

Both flaws are already being used in real‑world attacks. That raises the urgency for organizations that rely on these products but may not routinely update them, especially when switches and backup agents are treated as background infrastructure.

If a Zyxel switch is compromised, attackers can tap into traffic, change configurations and pivot deeper into the network. If a Veeam Agent is hijacked, backups themselves can be altered or destroyed, undermining recovery plans after incidents such as ransomware.

Key signs to follow now include the speed at which Zyxel and Veeam customers apply patches or mitigations, whether managed service providers report intrusions linked to these bugs, and whether high‑profile breaches are eventually traced back to exploitation of these vulnerabilities.
