Attacker drained configs and root hashes from 996 Zyxel switches; CISA gives agencies until Thursday
CVE-2026-7273 was patched in June, but GreyNoise says exploitation began around August 17 across 48 countries.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
A Chinese-speaking threat actor has exploited a flaw in unpatched Zyxel GS1900 Smart Managed Switches and exfiltrated sensitive data from 996 devices in 48 countries, GreyNoise reported on Monday. The affected switches sit predominantly in Italy, the United States, Taiwan, South Korea and other EU countries, and the GS1900 line is typically deployed in small offices, schools, hotels and retail shops. CVE-2026-7273 is a stack-based buffer overflow in a CGI program on firmware versions 2.90(XXXX.1)C0 and earlier. It lets an unauthenticated attacker on the local network run operating system commands through a crafted HTTP request. Zyxel privately received the report and shipped fixed firmware on June 16. GreyNoise says the attacks began on or about August 17, and that the actor collected device configurations, networking information and hashed root-level credentials; 564 of the victim devices were still using factory default credentials. The exploit code sat inside a Python script. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on Monday and ordered Federal Civilian Executive Branch agencies to secure their switches by Thursday under Binding Operational Directive 26-04. Zyxel has not yet updated its advisory to confirm active exploitation. CISA urged all organizations, not only federal agencies, to prioritize the fix.