Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

A trio of critical vulnerabilities in widely used network equipment and data backup software has left thousands of organizations exposed to devastating cyber attacks. The flaws, discovered in Zyxel’s networking devices and Veeam’s cloud-based backup solution, have been confirmed by multiple sources as being actively exploited in the wild, giving attackers unfettered access to compromised systems.

The affected products include Zyxel’s USG and ATP series firewalls, which are used by numerous businesses and government agencies worldwide, as well as Veeam’s Backup & Replication software, a popular choice among organizations seeking to safeguard their critical data. The vulnerabilities, collectively known as CVE-2026-1234, allow attackers to gain Command and SYSTEM-level access, essentially granting them free rein over compromised systems.

At the heart of this issue lies the concept of identity exposure, where an attacker leverages legitimate credentials or authentication mechanisms to bypass security controls and gain elevated privileges. In the case of these vulnerabilities, attackers can exploit weaknesses in authentication protocols or configuration settings to escalate their privileges, often with minimal effort required. This is particularly concerning given that many organizations rely on Zyxel’s networking devices for secure internet connectivity and Veeam’s backup solution for data protection.

The exploitation of these flaws has been tied to multiple instances of active attacks, where attackers have used them to breach critical systems, steal sensitive data, and disrupt business operations. This includes high-profile cases involving government agencies, healthcare providers, and financial institutions. While the full scope of the affected organizations remains unclear, it is evident that thousands of entities worldwide are potentially at risk.

In light of these findings, security teams must prioritize patching and upgrading their systems to address these vulnerabilities as quickly as possible. This includes implementing robust authentication mechanisms, regular security audits, and monitoring for suspicious activity. Furthermore, organizations should re-evaluate their disaster recovery plans and backup procedures to ensure that they can withstand potential breaches.

As the cybersecurity landscape continues to evolve, it is essential for organizations to remain vigilant against emerging threats and vulnerabilities. By staying informed, prioritizing patch management, and implementing robust security controls, businesses can mitigate the risks associated with these flaws and protect themselves from devastating cyber attacks.


Source: The Hacker News — 2026-09-22