CISA adds CVE-2026-7273 to Known Exploited Vulnerabilities
On Monday the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 — a now-patched stack-based buffer overflow in Zyxel GS1900 series switches with a CVSS score of 8.8 — to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. CISA did not disclose who was behind the exploitation, when attacks began, how many organizations were targeted, how many compromises succeeded, or what attackers did after gaining access to the vulnerable service.
Technical exposure in Zyxel GS1900 family and available fixes
The vulnerability resides in the CGI program of the GS1900 firmware and could permit arbitrary OS command execution via a crafted HTTP request against a LAN-facing service, Zyxel said. Zyxel credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS with discovering and reporting the defect.
Zyxel reported fixes for specific GS1900 model firmware lines; affected versions and their patched releases are:
- GS1900-8 2.90(AAHH.1)C0 and earlier — fixed in 2.90(AAHH.2)C0
- GS1900-8HP 2.90(AAHI.1)C0 and earlier — fixed in 2.90(AAHI.2)C0
- GS1900-10HP 2.90(AAZI.1)C0 and earlier — fixed in 2.90(AAZI.2)C0
- GS1900-16 2.90(AAHJ.1)C0 and earlier — fixed in 2.90(AAHJ.2)C0
- GS1900-24 2.90(AAHL.1)C0 and earlier — fixed in 2.90(AAHL.2)C0
- GS1900-24E 2.90(AAHK.1)C0 and earlier — fixed in 2.90(AAHK.2)C0
- GS1900-24EP 2.90(ABTO.1)C0 and earlier — fixed in 2.90(ABTO.2)C0
- GS1900-24HPv2 2.90(ABTP.1)C0 and earlier — fixed in 2.90(ABTP.2)C0
- GS1900-48 2.90(AAHN.1)C0 and earlier — fixed in 2.90(AAHN.2)C0
- GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier — fixed in 2.90(ABTQ.2)C0
As of this article, Zyxel had not revised its advisory to confirm the active exploitation that CISA cited when adding the defect to KEV.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleActive exploitation of Veeam Agent local privilege escalation (CVE-2026-32996)
Separately, Arctic Wolf warned of active exploitation of CVE-2026-32996, a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows scored 7.3. According to Arctic Wolf, the flaw resides in the Veeam Endpoint Backup service's handling of elevated client sessions over the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe.
Arctic Wolf said the service caches an elevated administrator principal against a client-controlled session UID that is not bound to the requesting user or connection. Because those elevated session UIDs are written to C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log — a file that standard users can read — an attacker with local access can obtain a valid UID and use it to execute commands as SYSTEM. A public GitHub proof-of-concept demonstrates this by running whoami and writing the output to a file.
Federal Civilian Executive Branch (FCEB) required actions and timelines
Because CISA designated the Zyxel flaw as a known exploited vulnerability, Federal Civilian Executive Branch agencies are required to apply the fixes by September 24, 2026, for optimal protection. The advisory places a short window on remediation for the listed GS1900 firmware variants.
How federal agencies, enterprise security teams, and endpoint administrators will act
- Federal agencies: FCEB agencies face a firm deadline — apply Zyxel GS1900 firmware updates by September 24, 2026 — and must verify that managed devices are not running the vulnerable firmware revisions listed above.
- Enterprise security teams: Network teams should prioritize LAN-facing Zyxel GS1900 switches for firmware upgrades to the indicated patched releases and audit internal network segments for devices still reporting older GS1900 firmware. Endpoint teams should treat Veeam Agent exploits as requiring local access and focus on limiting local privilege abuse and monitoring for unexpected SYSTEM-level process creation tied to Veeam components.
- Endpoint administrators: Those managing Veeam Agent for Windows should review Veeam-related logs at C:\ProgramData\Veeam\Endpoint\ and apply vendor patches or configuration changes that remove the ability for standard users to exploit session UIDs stored in logs, using the public proof-of-concept only in controlled test environments.
Two distinct vulnerabilities — one enabling unauthenticated, LAN-based command execution on a family of network switches and another enabling elevation to SYSTEM on Windows endpoints — are now tied to active exploitation and remediation steps. Patches and firmware updates exist for the enumerated Zyxel GS1900 releases and the Veeam Agent issue has a public proof-of-concept; what remains publicly unspecified is the scope and provenance of the exploitation CISA notes. Agencies and administrators must act quickly to apply the named fixes and confirm their environments no longer show the vulnerable firmware or unmitigated Veeam configurations.




