The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a patched security vulnerability affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog after receiving evidence that the flaw is being actively exploited. Tracked as CVE-2026-7273, the vulnerability has a CVSS score of 8.8 and involves a stack based buffer overflow issue in the CGI program of affected Zyxel switch firmware. The flaw could allow an unauthenticated attacker with access to the local network to execute operating system commands through specially crafted HTTP requests. Zyxel disclosed the vulnerability in June 2026 and released firmware updates addressing affected versions. The issue impacts multiple GS1900 models, including GS1900 8, GS1900 8HP, GS1900 10HP, GS1900 16, GS1900 24, GS1900 24E, GS1900 24EP, GS1900 24HPv2, GS1900 48, and GS1900 48HPv2. Organizations using these devices are advised to apply the available firmware updates to reduce potential exposure.
The addition of CVE-2026-7273 to CISA’s catalog follows research from GreyNoise, which reported observing exploitation activity targeting Zyxel switches. According to GreyNoise, a suspected Chinese speaking malicious cyber actor has been using the vulnerability since August 17, 2026, and successfully exploited hundreds of devices across multiple countries. The company reported that 996 Zyxel switches across 48 countries, including Italy, the United States, Taiwan, France, and South Korea, were affected during the observed activity. GreyNoise said the exploitation involved using the Trivial File Transfer Protocol (TFTP) utility to retrieve and execute a custom collection script. The collected information reportedly included device configurations, hashed root level credentials, and network related details. Researchers also noted that the exploit code was contained within a heavily obfuscated Python script using the commercial PyArmor tool. The script appeared to target specific GS1900 firmware versions while also including options that could allow adjustments for other affected firmware versions. Zyxel credited researchers from ISCAS, including Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo, for identifying and reporting the vulnerability.
Security researchers have also observed possible overlaps between the activity targeting Zyxel devices and other campaigns involving different vulnerabilities. Acronis recently tracked related activity under the name Red Heron after reporting exploitation of a Gitea vulnerability affecting internet exposed instances. Researchers have observed possible connections involving vulnerabilities in several products, including Gitea, UniFi OS, Flowise, WordPress, Linux kernel, Nuclio, SENAITE LIMS, Proxmox VE, and Palo Alto Networks PAN OS GlobalProtect portals. However, researchers have described these links as overlaps in observed activity rather than confirmed attribution. In response to the active exploitation reports, Federal Civilian Executive Branch agencies have been instructed to apply available fixes for CVE-2026-7273 by September 24, 2026. Security teams are encouraged to review affected Zyxel deployments, verify firmware versions, and monitor network activity for signs of unauthorized access.
Separately, cybersecurity company Arctic Wolf has warned about active exploitation of another vulnerability affecting Veeam Agent for Microsoft Windows. Tracked as CVE-2026-32996 with a CVSS score of 7.3, the flaw is a local privilege escalation issue that could allow an attacker with local access to gain SYSTEM level control on affected endpoints. Arctic Wolf explained that the vulnerability exists in the way Veeam Endpoint Backup service manages elevated client sessions through a local gRPC named pipe. The service stores elevated administrator session information using a session identifier that is not properly tied to the requesting user or connection. Researchers said standard users could access log information containing valid session identifiers from C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log and potentially misuse them to execute commands with SYSTEM privileges. A public proof of concept demonstrates the issue by executing commands and saving output to a file. Organizations using Veeam Agent for Windows are advised to review vendor guidance and apply security updates to reduce the risk associated with this vulnerability.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.