CISA adds exploited Zyxel GS1900 flaw to KEV as Veeam bug raises SYSTEM risk

CISA has added CVE-2026-7273, a vulnerability in Zyxel GS1900 series switch firmware, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw has a CVSS score of 8.8 and is a stack-based buffer overflow in a CGI program that can permit arbitrary operating-system command execution.
Zyxel said a LAN-based, unauthenticated attacker could exploit the issue using a crafted HTTP request. The vendor issued fixes in June 2026, but CISA has not disclosed who is exploiting the vulnerability, when exploitation began, how many organisations were targeted, or what actions attackers took after gaining access.
GS1900 firmware releases require attention
The affected product line includes GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48 and GS1900-48HPv2 switches. For each listed model, Zyxel fixed the issue in the corresponding 2.90 firmware release ending in .2)C0, replacing the earlier release ending in .1)C0.
For example, GS1900-8 devices should move from 2.90(AAHH.1)C0 or earlier to 2.90(AAHH.2)C0, while GS1900-24EP devices should move from 2.90(ABTO.1)C0 or earlier to 2.90(ABTO.2)C0. Federal Civilian Executive Branch agencies must apply the fixes by September 24, 2026.
The discovery was credited by Zyxel to Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu and Tianyue Luo of ISCAS. Zyxel had not updated its own alert to confirm active exploitation at the time of publication.
Veeam Agent flaw enables local SYSTEM access
Arctic Wolf also warned of active exploitation of CVE-2026-32996 in Veeam Agent for Microsoft Windows. Rated 7.3, the local privilege-escalation issue can enable an attacker who already has local access to obtain SYSTEM-level control of an affected endpoint.
The problem lies in how the Veeam Endpoint Backup service handles elevated client sessions over the local gRPC named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe. Arctic Wolf said the service caches an elevated administrator principal against a client-controlled session UID without binding that UID to the requesting user or connection.
Elevated session UIDs are recorded in C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log, a log that standard users can read. An attacker can obtain a valid UID and abuse it to execute commands as SYSTEM; a public GitHub proof of concept demonstrates this by running whoami and writing the output to a file.
Operational response
The combination of an actively exploited network-device flaw and a local endpoint escalation path reinforces the exposure patterns tracked in exposure patterns tracked in enterprise environments across enterprise environments. Security teams should identify GS1900 devices on vulnerable firmware, deploy Zyxel’s model-specific updates, and confirm that management access is limited to trusted network paths.
Teams using Veeam Agent for Microsoft Windows should assess affected endpoints for the local privilege-escalation condition, prioritise remediation where untrusted local access is possible, and review endpoint controls. The practical implication is to treat both fixes as urgent inventory and patch-management work: one addresses unauthenticated command execution on LAN-accessible switches, while the other can turn existing local access into SYSTEM control.

