www.zyxel.com Zyxel and Veeam Vulnerabilities Under Active Exploitation
Article Content
- •CISA added CVE-2026-7273 to its KEV catalog due to active exploitation.
- •Zyxel's GS1900 series switches are vulnerable to a stack-based buffer overflow.
- •Active exploitation of Veeam Agent for Windows allows SYSTEM-level control.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Zyxel GS1900 series switches (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog due to active exploitation. This stack-based buffer overflow flaw allows unauthenticated attackers to execute OS commands via crafted HTTP requests. Zyxel released patches for affected firmware versions on June 16, 2026, and federal agencies must apply these fixes by September 24, 2026. Concurrently, Arctic Wolf reported active exploitation of a local privilege escalation vulnerability in Veeam Agent for Windows (CVE-2026-32996), enabling attackers with local access to gain SYSTEM-level control. The Veeam vulnerability stems from improper handling of elevated client sessions, and a public proof-of-concept (PoC) was released on September 16, 2026. Both vulnerabilities pose significant risks to organizations using these products.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Zyxel and CVE-2026-32996 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…