By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Zyxel and Veeam Vulnerabilities Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that both flaws are currently being actively exploited by malicious actors. The first vulnerability affects Zyxel GS1900 series network switches and is tracked as CVE-2026-7273. This flaw, which carries a CVSS score of 8.8, is a stack-based buffer overflow vulnerability that allows for arbitrary code execution. The KEV catalog entry, published on Monday, cites evidence of active exploitation, meaning that attackers have already leveraged this weakness to compromise systems. The Zyxel GS1900 series are managed switches commonly used in small to medium-sized businesses for network infrastructure management. Exploitation of this vulnerability could grant attackers significant control over the affected network devices, potentially leading to network disruption or further infiltration.
In parallel, CISA also highlighted a critical vulnerability affecting Veeam Backup Enterprise Manager (VBEM), identified as CVE-2024-29849. This vulnerability, rated with a CVSS score of 9.8, is a critical authentication bypass flaw. Successful exploitation allows an unauthenticated attacker to gain administrative access to the VBEM server. This level of access is particularly concerning as VBEM is a central component for managing Veeam's backup and recovery solutions. Compromising VBEM could enable attackers to disable backups, delete backup data, or even use the compromised backup infrastructure to launch further attacks across an organization's network. The inclusion of this vulnerability in the KEV catalog underscores the immediate threat it poses to organizations relying on Veeam for data protection.
CISA mandates that U.S. federal civilian executive branch agencies must apply available patches or mitigations for vulnerabilities listed in the KEV catalog by specific deadlines to protect their networks. While this mandate applies to federal agencies, the inclusion of these vulnerabilities in the KEV catalog serves as a strong warning to all organizations, regardless of sector, to prioritize patching and implementing security measures. The active exploitation of both the Zyxel and Veeam vulnerabilities suggests that attackers are actively seeking and exploiting these weaknesses to gain unauthorized access and control. Organizations using Zyxel GS1900 switches or Veeam Backup Enterprise Manager are strongly advised to review their security configurations and apply any available updates or workarounds immediately to mitigate the risk of compromise. The nature of these vulnerabilities, allowing for arbitrary code execution and administrative access, highlights the critical importance of timely patch management and robust cybersecurity practices in defending against sophisticated threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.