Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
Reported exploitedZyXEL GS1900Veeam Agent for WindowsOur summary
A Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries and stealing configurations, network details, and hashed root credentials. The stack-based buffer overflow affects firmware 2.90(XXXX.1)C0 and earlier and enables unauthenticated command execution over LAN; CISA has listed it as exploited, while CVE-2026-32996 in Veeam Agent for Windows is also under active attack and should be remediated by upgrading Veeam Backup & Replication to 13.0.2.29 or later.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.