Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the US, Taiwan, South Korea, and a number of EU countries. CVE-2026-7273 exploitation is part of an unfolding operation The Zyxel GS1900 Series is a line of Gigabit Ethernet switches aimed at small and mid-sized business … More → The post Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) appeared first on Help Net Security .

·Help Net Security
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8. 8), to its Known Exploited Vulnerabilities (KEV) catalog . The flaw is a stack-based buffer overflow that could allow attackers to execute arbitrary operating system commands. “A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.” reads the advisory . The vulnerability affects the CGI component of Zyxel’s GS1900 switch firmware.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

[CISA] CVE-2026-7273 - Confirmed Exploitation

CVE-2026-7273 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-21 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-21 Asserted: 2026-09-21

·CISA KEV
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-72739 Detail - National Institute of Standards and Technology (.gov)

CVE-2026-72739 Detail National Institute of Standards and Technology (.gov)

·NVD
Read →

You've reached the end of current stories for this search.