Cyber Resilience
← All news
Corroborated

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

Sources (2)
What this means for you — Security leader:CISA added CVE-2026-7273 (Zyxel GS1900 switches) to its KEV catalog after confirmed active exploitation granting command execution. Patch immediately or disable remote management if unpatched devices remain in your environment.
What this means for you — Lean IT orgs:If you use Zyxel GS1900 switches, check the firmware version today and update to the latest release or turn off remote admin access. Attackers have already compromised nearly 1000 unpatched units worldwide.
What this means for you — MSP:Scan all client environments for Zyxel GS1900 switches; CVE-2026-7273 is under active exploitation. Apply the vendor patch or disable remote management on any unpatched devices immediately.
What this means for you — Researcher:GreyNoise observed a Chinese-speaking actor exploiting CVE-2026-7273 in Zyxel GS1900 switches since August, compromising 996 devices across 48 countries and exfiltrating data.