Skip to content
Zyxel and Veeam Vulnerabilities Under Active Exploitation

Zyxel and Veeam Vulnerabilities Under Active Exploitation

First seen 22 Sep 2026, 08:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 09:53 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Zyxel GS1900 series switches (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog due to active exploitation. This stack-based buffer overflow flaw allows unauthenticated attackers to execute OS commands via crafted HTTP requests. Zyxel released patches for affected firmware versions on June 16, 2026, and federal agencies must apply these fixes by September 24, 2026. Concurrently, Arctic Wolf reported active exploitation of a local privilege escalation vulnerability in Veeam Agent for Windows (CVE-2026-32996), enabling attackers with local access to gain SYSTEM-level control. The Veeam vulnerability stems from improper handling of elevated client sessions, and a public proof-of-concept (PoC) was released on September 16, 2026. Both vulnerabilities pose significant risks to organizations using these products.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-28
CVE-2026-32996 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-16
Zyxel releases patches for GS1900 series
Patches were released to address a stack-based buffer overflow vulnerability affecting the GS1900 series switches.
Zyxel
2026-09-16
Public PoC for Veeam vulnerability released
A public proof-of-concept demonstrating exploitation of CVE-2026-32996 was made available.
Thehackernews
2026-09-21
CVE-2026-7273 added to CISA KEV
CISA confirmed active exploitation of the Zyxel vulnerability and added it to its Known Exploited Vulnerabilities catalog.
Thehackernews
2026-09-22
Zyxel and Veeam vulnerabilities reported
Both vulnerabilities are under active exploitation, prompting urgent patching recommendations for affected organizations.
Thehackernews

More articles in this cluster (3)

Following this threat?

Track Zyxel and CVE-2026-32996 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed