CVE Tools
Back to feed
Exploited in the wild ZyXEL GS1900 data-breach Veeam Agent for Windows ZyXEL rce

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

Help Net Security·By Zeljka Zorz··3 min read
CVE Tools coverage

A Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries and stealing configurations, network details, and hashed root credentials. The stack-based buffer overflow affects firmware 2.90(XXXX.1)C0 and earlier and enables unauthenticated command execution over LAN; CISA has listed it as exploited, while CVE-2026-32996 in Veeam Agent for Windows is also under active attack and should be remediated by upgrading Veeam Backup & Replication to 13.0.2.29 or later.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store