The record
Written from the 1 report below. Nothing here is unsourced.
- CISA added a buffer overflow vulnerability in Zyxel GS1900 series switches to its Known Exploited Vulnerabilities catalog.
- Federal agencies must patch these devices by September 24, 2026.
- Separately, Arctic Wolf reported that a local privilege escalation flaw in Veeam Agent for Windows is being exploited to gain SYSTEM-level access.
- Attackers use this Veeam flaw to execute commands after obtaining a valid user ID from service logs.
What to watch next
- Any additional guidance from CISA regarding the Zyxel vulnerability exploitation scope.
- Zyxel's potential update to its security advisory confirming active exploitation.
Coverage1
1 report
English national1
All filed from India
Named United States · Veeam · Zyxel · Arctic Wolf · CISA · Institute of Software Chinese Academy of Sciences · Jingzheng Wu · Jun Cao · Lei Gu · Tianyue Luo · Zhiqing Rui
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
