Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

Summary

CISA has added a vulnerability in Zyxel GS1900 series switches to its Known Exploited Vulnerabilities catalog due to active exploitation. The flaw, CVE-2026-7273, is a stack-based buffer overflow with a CVSS score of 8.8, allowing for arbitrary code execution.

IFF Assessment

FOE

The discovery of active exploitation of a critical vulnerability in network infrastructure presents a direct threat to defenders.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 24, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating the CVE-2026-7273 vulnerability in Zyxel GS1900 switches, as it is actively being exploited. The ability to achieve arbitrary code execution highlights the need for robust network segmentation and monitoring to detect and prevent such attacks.

Read Full Story →