The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

CISA has added CVE-2026-7273, a stack-based buffer overflow vulnerability in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation by suspected Chinese threat actors. The attackers successfully compromised 996 Zyxel switches across 48 countries since August 2026, using crafted HTTP requests to execute operating system commands and deploy TFTP tools for data exfiltration. Simultaneously, Arctic Wolf reported active exploitation of CVE-2026-32996 in Veeam Agent for Windows, allowing local privilege escalation to SYSTEM-level access through manipulation of gRPC named pipe sessions.

These incidents highlight the growing trend of threat actors rapidly weaponizing newly disclosed vulnerabilities to target network infrastructure and backup systems, emphasizing the critical need for immediate patch deployment and enhanced monitoring of privileged access controls in enterprise environments.

Why This Matters Now

Organizations face immediate risk as threat actors are actively exploiting critical vulnerabilities in widely-deployed network switches and backup software, requiring urgent patching and enhanced monitoring to prevent data exfiltration and system compromise.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organizations should immediately update Zyxel GS1900 switches to firmware version 2.90 or later and patch Veeam Agent for Windows to address CVE-2026-32996, while implementing network segmentation and monitoring for anomalous TFTP traffic.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the scope and impact of this multi-stage attack by constraining lateral movement and limiting the blast radius across the compromised network infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While initial exploitation of vulnerable switches may still occur, comprehensive network visibility could likely enable faster detection of anomalous HTTP traffic patterns and unauthorized device behavior across the infrastructure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust microsegmentation policies would likely limit the scope of elevated privileges by restricting which resources compromised accounts could access, even with SYSTEM-level credentials on individual endpoints.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Strict east-west traffic inspection and segmentation policies would likely significantly constrain the attacker's ability to pivot between network segments and access additional systems beyond the initially compromised switches.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility across network segments could likely detect and constrain unauthorized TFTP communications and suspicious script execution patterns, limiting the effectiveness of remote command channels.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies and data loss prevention controls would likely constrain large-scale exfiltration operations by blocking or limiting unauthorized outbound data transfers from network infrastructure devices.

Impact (Mitigations)

While some network devices may remain compromised, the overall impact would likely be significantly reduced through limited blast radius and constrained access to connected systems and sensitive data flows.

Impact at a Glance

Affected Business Functions

  • Network Infrastructure Management
  • Data Center Operations
  • Backup and Recovery Services
  • Enterprise System Administration
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $250,000

Data Exposure

Network configurations, hashed root-level credentials, networking topology information from 996 compromised Zyxel switches across 48 countries. Potential for lateral movement and privilege escalation on Windows endpoints with Veeam agents installed.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between network devices and endpoints
  • • Deploy Egress Security & Policy Enforcement to block unauthorized TFTP and data exfiltration attempts to external destinations
  • • Enable Multicloud Visibility & Control to detect anomalous interactions and repeated malformed HTTP requests targeting vulnerable services
  • • Activate Inline IPS (Suricata) with current CVE signatures to identify and block known exploit patterns for CVE-2026-7273 and similar vulnerabilities
  • • Establish East-West Traffic Security monitoring to detect and prevent workload-to-workload communications from compromised network infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image