Updated: GreyNoise Reports Exploitation of Vulnerability in 996 Zyxel GS1900 Switches

According to secondary reports, GreyNoise recorded a campaign that allegedly compromised 996 Zyxel GS1900 switches in 48 countries through CVE-2026-7273. CISA has already added the vulnerability to its list of actively exploited vulnerabilities.

Updated: According to independently cited reports, GreyNoise documented a campaign that allegedly compromised 996 Zyxel GS1900 switches in 48 countries through CVE-2026-7273.

Zyxel GS1900 attacks using CVE-2026-7273 reportedly affected 996 managed switches in 48 countries, according to reports citing GreyNoise researchers. The activity allegedly took place on August 17, 2026. On September 21, the U.S. agency CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog, confirming that active exploitation was being tracked.

This clarifies previously public information: this was not merely unspecified exploitation recorded in the KEV catalog, but, according to GreyNoise telemetry, a specific campaign involving nearly one thousand affected devices. However, the device count and geographic scope come from GreyNoise’s assessment, not from an announcement by Zyxel or CISA.

Zyxel GS1900 attacks exploited a flaw accessible from the LAN

Zyxel released fixed firmware on June 16, 2026, for ten models in the GS1900 series. CVE-2026-7273 could allow an unauthenticated attacker with access to the same local network to execute system commands. The attack requires a crafted HTTP request to the device.

The attack vector is therefore tied to the local network. Adding the vulnerability to KEV does not, by itself, confirm direct exploitation of switches exposed to the internet. However, a compromised managed switch could provide an attacker with a position inside the internal network.

Administrators of affected devices should promptly verify the model and firmware version in use, deploy the fix according to Zyxel’s instructions, and review management interfaces, configurations, and available logs. Particular attention should be paid to administrative access from untrusted or unnecessarily broad network segments.

Campaign attribution has not yet been confirmed

According to the cited reports, GreyNoise identified overlaps that led it to assess the activity as potentially related to a Chinese-speaking actor or the Red Heron group. However, this is not a publicly confirmed attribution by a government agency. The original GreyNoise technical report, including indicators of compromise and detailed forensic data, is not yet available.

The reports also mention the theft of sensitive data, but this claim is based on GreyNoise telemetry and assessment. Zyxel and CISA have not confirmed this finding in their public materials.

Veeam is a separate case

CVE-2026-32996 in Veeam Agent for Microsoft Windows also appeared in connection with this alert. It is a patched local privilege-escalation vulnerability; Veeam lists the fix in version Veeam Backup & Replication 13.0.2.29.

However, there is no publicly verified evidence confirming active exploitation of the Veeam vulnerability. The incident involving Zyxel switches therefore cannot be presented as a campaign that exploited both vulnerabilities with equal confirmation.

What to watch next

  • publication of the GreyNoise technical report, including indicators of compromise,
  • any forensic details or attribution clarification from CISA, Zyxel, or independent researchers,
  • whether CISA adds CVE-2026-32996 to the KEV catalog or Veeam confirms real-world exploitation of the vulnerability.

Sources

  • Zyxel security advisory – Zyxel confirms the nature of CVE-2026-7273, the unauthenticated LAN vector, the ability to execute system commands, and available fixes for ten models.
  • Veeam KB4852 – Veeam describes CVE-2026-32996 as a local privilege escalation and lists fixed release 13.0.2.29; it does not mention active exploitation.
  • Cybersecurity Dive – Reports GreyNoise’s account of CVE-2026-7273 exploitation on 996 switches in 48 countries and a cautious link between the actor and Red Heron.
  • iThome – Independently reports GreyNoise data on 996 compromised switches, 48 countries, and suspected ties to Red Heron.

Verified and updated: September 22, 2026 15:24

Sharing