Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: network-switch (2 articles)Clear

CISA flags exploited Zyxel switch flaw enabling unauthenticated command execution over the LAN

CISA added a Zyxel GS1900 series switch flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation. Tracked as CVE-2026-7273 and rated 8.8, it is a stack-based buffer overflow in the switch firmware's CGI program that lets a LAN-based, unauthenticated attacker run operating system commands through a crafted HTTP request. Zyxel patched it in June across the GS1900-8 through GS1900-48HPv2 models. GreyNoise reported that a suspected Chinese-speaking actor has weaponized the flaw since August 17, successfully exploiting and exfiltrating data from 996 Zyxel switches across 48 countries. Federal agencies must patch under the KEV directive, and other operators should treat exposed management interfaces as a priority.

Check
Inventory Zyxel GS1900 switches, confirm firmware against the fixed versions, and update immediately while removing switch management interfaces from untrusted LAN segments.
Affected
Unpatched GS1900 switches let a LAN-based unauthenticated attacker run operating system commands via crafted HTTP requests, and active campaigns are already exfiltrating data.
Fix
Apply Zyxel's June firmware fixes, segment and restrict switch management access, and hunt for signs of prior compromise on exposed devices.

Critical Cisco Nexus switch flaw lets unauthenticated attackers run code as root

Cisco patched a critical flaw in its Nexus 9000 data-center switches that lets an unauthenticated, remote attacker execute code as root. Tracked as CVE-2026-20212 and scored 9.8, the bug affects Nexus 9000 models built on Cisco's Silicon One chips and stems from a service that binds to an unrestricted address, leaving TCP ports 43210 and 43211 reachable in the default routing configuration. An attacker who can reach either port sends crafted input that runs with root privileges, and can also crash and reload the device. Cisco reported no known exploitation at disclosure and shipped fixed software, with an access-list workaround for those who cannot patch immediately.

Check
Identify Nexus 9000 switches using Silicon One chips, upgrade to fixed NX-OS releases, and until then apply the access-control-list workaround that blocks TCP ports 43210 and 43211 to the device.
Affected
Organizations running affected Cisco Nexus 9000 switches with Silicon One chips (CVE-2026-20212); a remote, unauthenticated attacker reaching the exposed ports can execute code as root or crash the device, no credentials needed.
Fix
Patch to fixed NX-OS software, apply the access-list workaround and temporary shield until then, restrict management-plane reachability to the switches, and monitor for unexpected connections to the affected ports.