CVE Tools
Back to feed
Exploited in the wild Zyxel GS1900 series switches network-edge Veeam Agent for Windows Zyxel privilege-escalation

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

CISA has added CVE-2026-7273, an actively exploited stack-based buffer overflow in Zyxel GS1900 series switch firmware, to its KEV catalog. The flaw affects specified GS1900 models through their listed 2.90 firmware releases and can let an unauthenticated LAN attacker run operating-system commands through a crafted HTTP request; federal agencies must apply fixes by September 24, 2026. Arctic Wolf also reported active exploitation of CVE-2026-32996 in Veeam Agent for Microsoft Windows, where a local attacker can reuse exposed elevated session identifiers to execute commands with SYSTEM privileges.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store