Two vulnerabilities in widely used network and backup products are being attacked in the wild, one giving unauthenticated command execution, the other SYSTEM-level control.
The Hacker News reports active exploitation of two enterprise flaws. The first, CVE-2026-7273 (CVSS 8.8), is a stack-based buffer overflow in Zyxel GS1900 series switches that lets an unauthenticated attacker on the local network run operating-system commands through a crafted HTTP request. Ten GS1900 models are affected, fixes are available, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog with a federal patch deadline of September 24, 2026.
The second, CVE-2026-32996 (CVSS 7.3), is a local privilege-escalation flaw in the Veeam Agent for Windows that can hand an attacker with local access SYSTEM-level control. It stems from improper handling of elevated sessions over local gRPC named pipes, where elevated user IDs cached in readable log files can be abused to bypass authentication. The Zyxel issue was reported by researchers at ISCAS.
Why it matters: network and backup infrastructure are prime targets, and attackers move fast once a flaw is public. Timely patching, monitoring and least-privilege access are baseline for enterprise security, and part of what we operate for clients.