Skip to content
feed: live
>_0dayNews
cisa kev
● Breaking

Zyxel, Veeam Flaws Confirmed Under Active Exploitation

CISA added Zyxel GS1900 CVE-2026-7273 to its KEV catalog September 21. Veeam Agent CVE-2026-32996 also actively exploited. Patches available for both.

Zyxel, Veeam Flaws Confirmed Under Active Exploitation
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series managed switches, to its Known Exploited Vulnerabilities catalog on September 21. Federal Civilian Executive Branch agencies have until September 24 to patch under BOD 26-04. Separately, security researchers at Arctic Wolf flagged CVE-2026-32996, a local privilege escalation in Veeam Agent for Microsoft Windows (CVSS 7.3, high), as actively exploited in the wild.

Zyxel GS1900: command execution from the LAN

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of GS1900 series switches, rated CVSS 8.8 high. A LAN-based, unauthenticated attacker can send a crafted HTTP request and execute arbitrary OS commands on the switch.

The GS1900 line covers eight-port to 48-port managed switches common in SMB and enterprise distribution layers. Zyxel has patched all affected models: the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2. Specific updated firmware version strings for each model are listed in Zyxel’s security advisory.

CISA’s September 24 deadline applies to federal networks. Patch it before then regardless of whether you’re a federal shop: unauthenticated command execution on managed switching infrastructure is not something to defer.

Veeam Agent: SYSTEM from a local foothold

CVE-2026-32996 is a local privilege escalation in Veeam Agent for Microsoft Windows, rated CVSS 7.3 high. An attacker with existing local access can escalate to SYSTEM-level control of the endpoint.

The “local” qualifier carries less weight on backup infrastructure than it sounds. Backup agents typically hold broad file-system access, backup credentials, and network paths. SYSTEM on a Veeam Agent host is a meaningful position, and confirmed wild exploitation means it is being used. Veeam has released a patch; the NVD record for CVE-2026-32996 has current version guidance.

Patch priority

Zyxel first: KEV catalog addition with a September 24 federal deadline and an unauthenticated network-accessible exploit path on managed switching infrastructure. Veeam second: local-access prerequisite raises the bar, but confirmed exploitation on backup agents warrants acting this week.

For context on CISA’s recent pace: WatchGuard Firebox exploitation via a CVSS 9.8 flaw was added to KEV earlier this month, as was the N-able N-central auth bypass on September 9. On Zyxel specifically: CVE-2023-28771 reached EPSS 0.99 three years post-patch, a reminder that unpatched Zyxel devices stay on exploit radar for a long time.

Related CVEs
  • [ HIGH ]CVE-2026-7273Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
  • [ HIGH ]CVE-2026-32996Veeam Agent for Windows Local Privilege Escalation

Found this useful? Share it.