Exploited Zyxel switches expose nearly 1,000 systems worldwide

Exploited Zyxel switches expose nearly 1,000 systems worldwide. Organizations using Zyxel GS1900 switches face confirmed exploitation across 996 devices in 48 countries.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 22nd, 2026.

Organizations using Zyxel GS1900 switches face confirmed exploitation across 996 devices in 48 countries. CISA added C V E dash 2026 dash 7273 to its Known Exploited Vulnerabilities catalog on September 21st, making this a clear patching priority. Researchers linked the activity to a Chinese-speaking actor that has targeted Zyxel, WordPress, and Ubiquiti systems since at least June. The broader campaign also stole thousands of documents from at least one Western government. Researchers suspect large language models may have helped develop custom tools, but that point remains unconfirmed.

This matters because compromised edge devices can provide access while looking like ordinary network infrastructure. The activity spans several products, so teams shouldn’t treat each affected platform as a separate and unrelated problem. Leaders should confirm that every internet-facing device is inventoried and has an accountable owner. Defenders should prioritize the Zyxel update, look for unauthorized administrator accounts, and review activity around affected switches.

Patch affected Zyxel switches immediately, then investigate account, configuration, and traffic changes that may have happened before remediation. Exposed edge infrastructure remains a practical route to persistent access and data theft.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Exploited Zyxel switches expose nearly 1,000 systems worldwide
Broadcast by