CISA added a Zyxel GS1900 series switch flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation. Tracked as CVE-2026-7273 and rated 8.8, it is a stack-based buffer overflow in the switch firmware's CGI program that lets a LAN-based, unauthenticated attacker run operating system commands through a crafted HTTP request. Zyxel patched it in June across the GS1900-8 through GS1900-48HPv2 models. GreyNoise reported that a suspected Chinese-speaking actor has weaponized the flaw since August 17, successfully exploiting and exfiltrating data from 996 Zyxel switches across 48 countries. Federal agencies must patch under the KEV directive, and other operators should treat exposed management interfaces as a priority.
Cisco patched a critical flaw in its Nexus 9000 data-center switches that lets an unauthenticated, remote attacker execute code as root. Tracked as CVE-2026-20212 and scored 9.8, the bug affects Nexus 9000 models built on Cisco's Silicon One chips and stems from a service that binds to an unrestricted address, leaving TCP ports 43210 and 43211 reachable in the default routing configuration. An attacker who can reach either port sends crafted input that runs with root privileges, and can also crash and reload the device. Cisco reported no known exploitation at disclosure and shipped fixed software, with an access-list workaround for those who cannot patch immediately.