A coordinated attack pattern is actively exploiting critical vulnerabilities in both Zyxel network switches and Veeam Backup & Replication systems, creating a dual threat that targets an organization's infrastructure and its primary recovery capability simultaneously.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a severe flaw in Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog. This formal acknowledgement, highlighted in a report from The Hacker News, confirms that threat actors are actively using the vulnerability, tracked as CVE-2026-7273, to gain command-line control of affected devices.

Concurrently, separate vulnerabilities in Veeam Backup & Replication software are also under active exploitation by threat actors. The simultaneous targeting points to a deliberate strategy: compromise network access points while crippling the systems designed to restore order after an attack.

The Zyxel vulnerability carries a high CVSS score of 8.8. It is a stack-based buffer overflow that, when exploited, allows a remote attacker to execute arbitrary commands on the switch with elevated privileges. Control over network hardware provides attackers with persistent access, the ability to monitor traffic, and a platform for moving laterally through the network.

The parallel attacks on Veeam systems strike at the heart of operational resilience. Backup repositories are the final line of defense against data loss from incidents like ransomware. By compromising these systems, attackers can prevent organizations from recovering clean data, thereby maximizing pressure during an incident.

This dual-front assault represents a sophisticated threat model designed to both infiltrate and disable an organization's defenses. Security experts note that a siloed approach—managing network infrastructure and data backups as separate domains—creates dangerous blind spots in the face of such coordinated attacks. Consequently, patching both systems transitions from a routine task to an urgent, integrated security imperative.

For IT administrators worldwide, the alert is clear. While CISA's KEV catalog inclusion formally mandates action for U.S. federal agencies, the confirmed active exploitation of both products makes remediation a top-priority directive for all organizations.

Recommended Actions for System Administrators: 1. Unified Inventory: Conduct an immediate audit to identify all Zyxel GS1900 switches and Veeam Backup & Replication installations within the environment. 2. Urgent Patch Deployment: Apply vendor-supplied patches for both products without delay. This is the primary and most effective control. 3. Segmentation for High-Risk Systems: For any critical systems that cannot be patched immediately, implement strict network segmentation. Isolate vulnerable switches from core assets and restrict administrative access to backup servers to essential personnel on trusted networks only. 4. Backup Security Review: Verify that backup repositories are not only patched but also segmented from the general network, and that their credentials are tightly controlled and changed regularly.

This incident underscores a critical evolution in attacker tactics: targeting the interdependent components of an organization's technology stack. Effective defense now demands integrated visibility and hardened security across both the network fabric and the data recovery infrastructure. Failing to address both targets of this attack chain leaves organizations dangerously exposed to catastrophic compromise and data loss.


一種協同攻擊模式正積極利用Zyxel網絡交換機及Veeam備份與複製系統中的嚴重漏洞,對組織的基礎設施及其主要恢復能力構成雙重威脅,使其同時成為攻擊目標。

美國網絡安全及基礎設施安全局(CISA)已將Zyxel GS1900系列交換機中的一個嚴重漏洞列入其已知遭利用漏洞(KEV)目錄。此項正式確認,經由《The Hacker News》的報導突出顯示,證實威脅行為者正積極利用追蹤編號為CVE-2026-7273的漏洞,以取得受影響設備的命令列控制權。

與此同時,Veeam備份與複製軟件中的其他漏洞亦正遭威脅行為者積極利用。這種同步攻擊指向一項蓄意策略:在癱瘓旨在攻擊後恢復秩序的系統之餘,同時入侵網絡訪問點。

該Zyxel漏洞的CVSS評分高達8.8。這是一項基於堆疊的緩衝區溢位漏洞,當被利用時,允許遠端攻擊者以提升權限在交換機上執行任意命令。控制網絡硬件可為攻擊者提供持久訪問權限、監控流量的能力,以及在網絡內進行橫向移動的平台。

針對Veeam系統的並行攻擊直擊運營韌性的核心。備份儲存庫是對抗勒索軟件等事件導致數據丟失的最後防線。通過入侵這些系統,攻擊者可阻止組織恢復潔淨數據,從而在事件期間施加最大壓力。

這種雙線攻擊代表了一種精密的威脅模型,旨在同時滲透及癱瘓組織的防禦體系。安全專家指出,面對此類協同攻擊時,將網絡基礎設施與數據備份視為獨立領域進行管理的孤立模式,會產生危險的盲點。因此,修補兩個系統已從常規任務轉變為緊急且整合性的安全指令。

對全球IT管理員而言,警示清晰明確。儘管CISA的KEV目錄納入正式要求美國聯邦機構採取行動,但兩個產品已證實的積極利用狀況,使得補救成為所有組織的優先級別指令。

系統管理員建議行動: 1. 統一盤點: 立即進行審計,識別環境內所有Zyxel GS1900交換機及Veeam備份與複製安裝。 2. 緊急部署修補程式: 毫不延遲地應用廠商提供的兩個產品修補程式。這是主要且最有效的控制措施。 3. 高風險系統分段: 對於任何無法立即修補的關鍵系統,實施嚴格的網絡分段。將存在漏洞的交換機與核心資產隔離,並限制備份伺服器的管理訪問權限,僅允許可信網絡上的必要人員訪問。 4. 備份安全審查: 驗證備份儲存庫不僅已修補,亦已與一般網絡分隔,且其憑證受到嚴格控制並定期更換。

此事件突顯攻擊者策略的關鍵演進:針對組織技術堆疊中相互依存的組件。現時有效的防禦需要網絡架構與數據恢復基礎設施的整合可見性及強化安全措施。未能同時應對此攻擊鏈的雙重目標,將使組織面臨嚴重入侵及數據丟失的巨大風險。

新聞來源 / Original News Source