# Active attacks on Zyxel GS1900 switches and Veeam Agent put internal corporate systems at direct risk

*Tuesday, September 22, 2026 at 6:19 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-22T06:19:02.948Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18536.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting serious vulnerabilities in Zyxel GS1900 switches and Veeam Agent for Windows that allow command execution from the local network and full SYSTEM control on Windows machines, turning core infrastructure and backup tools into entry points for deeper breaches.

Two widely used IT products have turned into live attack surfaces, as threat actors exploit fresh vulnerabilities in Zyxel switches and Veeam backup software to gain powerful access inside corporate networks.

Security researchers say attackers are actively targeting flaws in Zyxel GS1900 series network switches and in Veeam Agent for Windows. These products usually sit at the core of office and data‑center environments, quietly handling traffic and backups.

The bug in Zyxel’s GS1900 switches lets an attacker on the local network run operating system commands without any authentication. In practice, anyone who can reach the switch from the internal LAN can issue arbitrary commands without a password. Because managed switches act as central junctions for connected devices, a compromise there can expose large volumes of traffic and give attackers new paths deeper into the network.

The Veeam Agent for Windows issue gives a local attacker the ability to obtain SYSTEM‑level control on a Windows host. SYSTEM is the highest level of privilege in the Windows operating system. Once at that level, an attacker can install malware, pull data, disable defenses, or use the compromised machine as a pivot point to move further across an organization.

Although the Zyxel flaw requires local network access, many high‑impact intrusions unfold in stages: once someone has a foothold inside, weaknesses like this make it far easier to escalate and spread. A backup agent that can be abused for SYSTEM access, or a switch that runs commands for any user on the LAN, turns core infrastructure into a liability.

For organizations running these products, the practical test now is how quickly they can identify affected devices and apply fixes, and whether major intrusion campaigns start to include these exploits as standard tools. Incident reports that tie large breaches directly to exploited Zyxel GS1900 switches or Veeam Agent for Windows would be a clear sign that the risk has moved from technical advisory to full‑blown operational problem.
