Executive Summary
CISA has added CVE-2026-7273, a stack-based buffer overflow vulnerability in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation by suspected Chinese threat actors. The attackers successfully compromised 996 Zyxel switches across 48 countries since August 2026, using crafted HTTP requests to execute operating system commands and deploy TFTP tools for data exfiltration. Simultaneously, Arctic Wolf reported active exploitation of CVE-2026-32996 in Veeam Agent for Windows, allowing local privilege escalation to SYSTEM-level access through manipulation of gRPC named pipe sessions.
These incidents highlight the growing trend of threat actors rapidly weaponizing newly disclosed vulnerabilities to target network infrastructure and backup systems, emphasizing the critical need for immediate patch deployment and enhanced monitoring of privileged access controls in enterprise environments.
Why This Matters Now
Organizations face immediate risk as threat actors are actively exploiting critical vulnerabilities in widely-deployed network switches and backup software, requiring urgent patching and enhanced monitoring to prevent data exfiltration and system compromise.
Attack Path Analysis
Chinese-speaking threat actor Red Heron exploited CVE-2026-7273 stack buffer overflow in Zyxel GS1900 switches via crafted HTTP requests, executed TFTP to deploy Python collector scripts, exfiltrated configuration data and credentials from 996 switches across 48 countries, while simultaneously exploiting CVE-2026-32996 in Veeam Agent for privilege escalation to SYSTEM level access.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actor exploited CVE-2026-7273 stack-based buffer overflow in Zyxel GS1900 series switches through crafted HTTP requests to LAN-based interfaces without authentication
Related CVEs
CVE-2026-7273
CVSS 8.8A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900 series switches allows an unauthenticated LAN-based attacker to execute arbitrary operating system commands via crafted HTTP requests.
Affected Products:
Zyxel GS1900 Series Switches – GS1900-8 2.90(AAHH.1)C0 and earlier, GS1900-8HP 2.90(AAHI.1)C0 and earlier, GS1900-10HP 2.90(AAZI.1)C0 and earlier, GS1900-16 2.90(AAHJ.1)C0 and earlier, GS1900-24 2.90(AAHL.1)C0 and earlier, GS1900-24E 2.90(AAHK.1)C0 and earlier, GS1900-24EP 2.90(ABTO.1)C0 and earlier, GS1900-24HPv2 2.90(ABTP.1)C0 and earlier, GS1900-48 2.90(AAHN.1)C0 and earlier, GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier
Exploit Status:
exploited in the wildCVE-2026-32996
CVSS 7.3A local privilege escalation vulnerability in Veeam Agent for Microsoft Windows allows an attacker with local access to obtain SYSTEM-level control due to improper handling of elevated client sessions over gRPC named pipes.
Affected Products:
Veeam Agent for Microsoft Windows – Affected versions not specified
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: Unix Shell
Exploitation for Privilege Escalation
Process Injection
Data from Local System
Exfiltration Over C2 Channel
Obfuscated Files or Information
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External Vulnerability Scanning
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.02(g)
DORA – ICT Risk Management Framework
Control ID: Article 9
CISA ZTMM 2.0 – Network Segmentation
Control ID: 3.2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Networking
Zyxel GS1900 switches face active exploitation enabling OS command execution and data exfiltration of network configurations and credentials across enterprise infrastructures.
Information Technology/IT
Veeam backup systems vulnerable to local privilege escalation allowing SYSTEM-level control, compromising backup integrity and enterprise endpoint protection capabilities.
Financial Services
Critical network infrastructure vulnerabilities enable data exfiltration of sensitive financial configurations, threatening compliance with PCI DSS and operational security requirements.
Health Care / Life Sciences
Network switch and backup system compromises risk HIPAA violations through unauthorized access to patient data systems and healthcare infrastructure configurations.
Sources
- Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Accesshttps://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.htmlVerified
- CISA Adds One Known Exploited Vulnerability to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalogVerified
- Zyxel Security Advisory for Stack-Based Buffer Overflow Vulnerability in GS1900 Series Switcheshttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026Verified
- Arctic Wolf Active Exploitation Alert for CVE-2026-32996https://arcticwolf.com/resources/blog/update-active-exploitation-cve-2026-32996-of-veeam-agent/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope and impact of this multi-stage attack by constraining lateral movement and limiting the blast radius across the compromised network infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial exploitation of vulnerable switches may still occur, comprehensive network visibility could likely enable faster detection of anomalous HTTP traffic patterns and unauthorized device behavior across the infrastructure.
Control: Zero Trust Segmentation
Mitigation: Zero trust microsegmentation policies would likely limit the scope of elevated privileges by restricting which resources compromised accounts could access, even with SYSTEM-level credentials on individual endpoints.
Control: East-West Traffic Security
Mitigation: Strict east-west traffic inspection and segmentation policies would likely significantly constrain the attacker's ability to pivot between network segments and access additional systems beyond the initially compromised switches.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility across network segments could likely detect and constrain unauthorized TFTP communications and suspicious script execution patterns, limiting the effectiveness of remote command channels.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies and data loss prevention controls would likely constrain large-scale exfiltration operations by blocking or limiting unauthorized outbound data transfers from network infrastructure devices.
While some network devices may remain compromised, the overall impact would likely be significantly reduced through limited blast radius and constrained access to connected systems and sensitive data flows.
Impact at a Glance
Affected Business Functions
- Network Infrastructure Management
- Data Center Operations
- Backup and Recovery Services
- Enterprise System Administration
Estimated downtime: 3 days
Estimated loss: $250,000
Network configurations, hashed root-level credentials, networking topology information from 996 compromised Zyxel switches across 48 countries. Potential for lateral movement and privilege escalation on Windows endpoints with Veeam agents installed.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between network devices and endpoints
- • Deploy Egress Security & Policy Enforcement to block unauthorized TFTP and data exfiltration attempts to external destinations
- • Enable Multicloud Visibility & Control to detect anomalous interactions and repeated malformed HTTP requests targeting vulnerable services
- • Activate Inline IPS (Suricata) with current CVE signatures to identify and block known exploit patterns for CVE-2026-7273 and similar vulnerabilities
- • Establish East-West Traffic Security monitoring to detect and prevent workload-to-workload communications from compromised network infrastructure



