INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Zyxel Switch Vulnerability Exploited by Chinese Hackers for Data Theft

| 2026-09-22 11:55 CRITICAL HIGH EXPLOITED VULNERABILITY STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, with 996 devices compromised in August. The attack uses a heavily obfuscated Python script to extract hashed root credentials, configuration details, and networking information from affected devices. Meanwhile, the same threat actor was also seen using a chain of Ubiquiti vulnerabilities leading to remote code execution (RCE) and targeting WordPress installations in July, with over 18,000 sensitive records stolen from one western governmental organization's backend database. The attack exploits a stack-based buffer overflow vulnerability tracked as CVE-2026-7273, which was patched by ZyXEL in June but remains unpatched on many devices worldwide.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2024-40891, CVE-2026-7273 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-40891CVE-2024-40891 CVE-2026-7273CVE-2026-7273
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎June 16
Threat actors exploited a previously known vulnerability in Zyxel's products, prompting the company to release security updates on June 16.
‎17 September 2026
Threat actors used the newly added Zyxel vulnerability to target systems, with this being the first publicly documented case of exploitation in the wild.
‎September 22, 2026
U.S. CISA added the Zyxel vulnerability to its Known Exploited Vulnerabilities catalog on September 22, 2026.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
attribution Zyxel
‎2026/09/22
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, tracked as CVE-2026-7273.
organisation Known Exploited
organisation KEV
organisation CGI
organisation LAN
organisation ZyXEL GS1900 Smart Managed Switches
infrastructure Linux
organisation WordPress
organisation GreyNoise
organisation Recent ZyXEL Switch Vulnerability Exploited
organisation ZyXEL
organisation MCA
infrastructure 2.10-2
infrastructure 996 vulnerable devices
organisation Acronis
data_breach 564 credentials
data_breach 18,000 sensitive records
infrastructure 2.90
organisation Zyxel’s
financial 04 BOD
organisation CVE-2024-40891
organisation NFL
organisation CHANEL
‎September 24, 2026
CISA orders federal agencies to fix the Zyxel vulnerability by September 24, 2026.
Tactical Metrics
Metrics
infrastructure
‎2.10-2
Software Version
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
996
Vulnerable Devices
Metrics
data_breach
564
Credentials
Metrics
data_breach
18,000
Sensitive Records
Metrics
infrastructure
‎2.90
Software Version
Metrics
financial
4
Bod
Intelligence Sources