On Monday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a patched security flaw affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog.

The issue has been addressed in the following versions: - GS1900-8 2.90(AAHH.1)C0 and earlier - Fixed in 2.90(AAHH.2)C0 - GS1900-8HP 2.90(AAHI.1)C0 and earlier - Fixed in 2.90(AAHI.2)C0 - GS1900-10HP 2.90(AAZI.1)C0 and earlier - Fixed in 2.90(AAZI.2)C0 - GS1900-16 2.90(AAHJ.1)C0 and earlier - Fixed in 2.90(AAHJ.2)C0 - GS1900-24 2.90(AAHL.1)C0 and earlier - Fixed in 2.90(AAHL.2)C0 - GS1900-24E 2.90(AAHK.1)C0 and earlier - Fixed in 2.90(AAHK.2)C0 - GS1900-24HPv2 2.90(ABTP.1)C0 and earlier - Fixed in 2.90(ABTP.2)C0 - GS1900-48 2.90(AAHN.1)C0 and earlier - Fixed in 2.90(AAHN.2)C0 - GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier - Fixed in 2.90(ABTQ.2)C0 Arctic Wolf warned of active exploitation of a local privilege escalation flaw in Veeam Agent for Windows, allowing an attacker with local access to gain SYSTEM-level control of affected endpoints.