Attacker compromised nearly 1,000 Zyxel switches via CVE-2026-7273
GreyNoise reported that a Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched Zyxel GS1900 switches and exfiltrated data from 996 devices across 48 countries. The stack-based buffer overflow was fixed in June 2026, with attacks occurring around August 17; CISA added the flaw to its Known Exploited Vulnerabilities catalog with a September 24, 2026 deadline.
- 996 Zyxel GS1900 switches compromised across 48 countries
- Most victims located in Italy, the US, Taiwan and South Korea
- Flaw patched in June 2026, attacks occurred around August 17
- CISA orders federal agencies to remediate by September 24, 2026
Read next
Security