CISA Flags Active Exploits of Zyxel Switch and Veeam Backup Flaws in Updated KEV List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Monday that a critical vulnerability affecting Zyxel GS1900 series Ethernet switches has been added to its Known Exploited Vulnerabilities (KEV) catalog, confirming that threat actors are actively leveraging the flaw despite a patch being available.
The defect, identified by the vendor as CVE‑2024‑XXXX, allowed unauthenticated attackers to execute arbitrary commands and obtain system‑level privileges on affected devices. Zyxel released a firmware update earlier this month that resolves the issue, but CISA’s inclusion of the vulnerability in the KEV list underscores that some adversaries continue to target unpatched installations.
In parallel, CISA also highlighted ongoing exploitation of multiple vulnerabilities in Veeam Software's backup and recovery solutions. Those flaws grant attackers command‑execution capabilities and, in certain configurations, full system access, raising the risk of ransomware deployment or data exfiltration across enterprise environments that rely on Veeam for critical workloads.
The agency’s KEV catalog serves as a curated set of high‑impact vulnerabilities that have been observed in the wild. By flagging both the Zylox and Veeam weaknesses, CISA aims to prompt immediate remediation actions across federal and private sectors, urging organizations to apply patches, review network segmentation, and monitor for suspicious activity linked to the identified exploit techniques.
Security researchers have reported that the Zyxel exploit has been used in short‑lived intrusion campaigns targeting small‑to‑medium businesses, often as a foothold to move laterally within corporate networks. The Veeam attacks, meanwhile, appear in ransomware‑as‑a‑service offerings, where threat actors exploit backup software to encrypt data and demand payment.
Industry analysts note that the convergence of network‑infrastructure and data‑protection vulnerabilities presents a compounded threat. When an attacker can both control network switches and manipulate backup systems, the ability to isolate, disrupt, or destroy critical services increases dramatically.
Experts recommend a layered response: first, verify that all Zyxel GS1900 devices run the latest firmware; second, ensure Veeam products are updated to the versions that address the disclosed flaws; third, implement strict access controls and multi‑factor authentication for management interfaces; and fourth, employ continuous monitoring to detect anomalous command‑execution patterns.
Looking ahead, CISA plans to expand the KEV program to include more real‑time intelligence on active exploits, encouraging organizations to adopt a “patch‑first” posture while maintaining robust intrusion‑detection capabilities. The agency’s latest advisory serves as a reminder that even promptly released patches can be outpaced by attackers who target lagging systems, making rapid deployment and vigilant monitoring essential components of modern cyber resilience.
Comments (0)
Be the first to comment.
Join the discussion