Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
CISA has added CVE-2026-7273, an actively exploited stack-based buffer overflow in Zyxel GS1900 series switch firmware, to its KEV catalog. The flaw affects specified GS1900 models through their listed 2.90 firmware releases and can let an unauthenticated LAN attacker run operating-system commands through a crafted HTTP request; federal agencies must apply fixes by September 24, 2026. Arctic Wolf also reported active exploitation of CVE-2026-32996 in Veeam Agent for Microsoft Windows, where a local attacker can reuse exposed elevated session identifiers to execute commands with SYSTEM privileges.