Exploited in the wild ZyXEL GS1900 data-breach Veeam Agent for Windows ZyXEL rce
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
CVE Tools coverage
A Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries and stealing configurations, network details, and hashed root credentials. The stack-based buffer overflow affects firmware 2.90(XXXX.1)C0 and earlier and enables unauthenticated command execution over LAN; CISA has listed it as exploited, while CVE-2026-32996 in Veeam Agent for Windows is also under active attack and should be remediated by upgrading Veeam Backup & Replication to 13.0.2.29 or later.