Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Zyxel GS1900 Switch Exploit Hits 996 Devices as CISA Orders Federal Patch
    Technology

    Zyxel GS1900 Switch Exploit Hits 996 Devices as CISA Orders Federal Patch

    Gary BehanBy Gary Behan01/10/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Zyxel GS1900 switch exploit
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A Zyxel GS1900 switch exploit has compromised nearly 1,000 devices across 48 countries, prompting CISA to add CVE-2026-7273 to its Known Exploited Vulnerabilities catalogue and order Federal Civilian Executive Branch agencies to patch their switches by Thursday. The vulnerability has been attributed by threat intelligence company GreyNoise to a suspected Chinese-speaking malicious cyber actor, and the damage already done is considerably more specific than most KEV additions warrant.

    The flaw itself is a stack-based buffer overflow in the CGI programme of GS1900 series switches. It allows an unprivileged attacker on the local area network to execute operating system commands by sending maliciously crafted HTTP requests. Zyxel released firmware updates to address the issue on 16 June and advised customers to upgrade for what it called ‘optimal protection.’ The company has not yet updated its own advisory to confirm active exploitation in the wild.

    CISA was less equivocal. Adding CVE-2026-7273 to the KEV catalogue on Monday, the agency cited Binding Operational Directive 26-04 in mandating that FCEB agencies secure affected devices against ongoing attacks. ‘This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,’ CISA said, while also encouraging all organisations (not just federal ones) to treat KEV catalogue entries as remediation priorities.

    What the Zyxel GS1900 Switch Exploit Actually Stole

    GreyNoise published its own account on Monday, tracing the first signs of exploitation to the previous Thursday. According to Help Net Security, the attacks themselves occurred on or about 17 August, with the threat actor extracting device configuration data, networking information, and hashed root-level credentials from each compromised switch. GreyNoise confirmed this was ‘the first publicly documented case of exploitation in the wild’ of CVE-2026-7273 as of 17 September 2026.

    The method was deliberate and somewhat sophisticated. According to SecurityWeek, the threat actor deployed a heavily obfuscated Python script to carry out the exfiltration across 996 vulnerable devices. The geographic spread of victims skews towards Italy, the US, Taiwan, South Korea, and several EU countries, according to Help Net Security.

    One detail that stands out: 564 of the 996 compromised switches were running factory default credentials at the time of the attack, according to GreyNoise. That is more than half the victim pool handing over the keys with no resistance at all. It is a reminder that CVE exploitation and basic credential hygiene are not separate problems.

    A Familiar Pattern for Zyxel Devices

    The GS1900 series finds itself in this position partly for structural reasons. Zyxel devices are widely deployed by internet service providers as default equipment bundled into new service contracts, which means large numbers of them sit on networks with minimal post-installation configuration. That combination of broad deployment and inconsistent hardening makes them a recurring target.

    CISA currently tracks 13 Zyxel vulnerabilities across the company’s routers, switches, firewalls, and NAS devices that have been, or still are, actively exploited. The CVE-2026-7273 addition brings fresh urgency to that list, particularly given the documented exfiltration of credential data that could facilitate further access to compromised networks.

    The pattern also echoes an episode from February, when Zyxel disclosed that it had no plans to patch a pair of actively exploited zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers still available for purchase online. Rather than issuing fixes, the company advised customers to replace the hardware entirely. The GS1900 situation is different in that patches do exist, but the window between Zyxel’s June firmware release and confirmed exploitation underscores how slowly updates propagate across real-world deployments.

    Zyxel states that over 1 million businesses use its networking solutions across 150 markets worldwide. FCEB agencies have until Thursday to demonstrate they are not among the unpatched remainder; everyone else has no formal deadline, but 996 confirmed victims and a trove of harvested credentials provide a fairly compelling argument for urgency.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleBigCommerce Ribon app breach exposes shoppers at Master of Malt and beyond
    Next Article Exhibitors and hosted buyers to meet at Istanbul’s Eurasia Packaging 2026
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    EvilTokens PhaaS Takedown: Microsoft Seizes 50 Sites, Two Arrested in UK

    01/10/2026

    BigDiskBuster Windows Defender zero-day exploit freezes antivirus updates

    01/10/2026

    BigCommerce Ribon app breach exposes shoppers at Master of Malt and beyond

    30/09/2026

    Microsoft 365 Companion Apps Retirement Set for 16 December

    30/09/2026

    Ireland’s DPC hits Google with €403m location data fine

    30/09/2026

    September Windows Updates Trigger File History Backup Bug Across Windows 10 and 11

    29/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.