One operator, working in Chinese, spent part of August emptying configuration data out of 996 Zyxel GS1900 switches scattered across 48 countries. GreyNoise published the count this week.
The hole they used is CVE-2026-7273. Inside the switch firmware’s CGI program sits a stack-based buffer overflow, rated 8.8. Anyone able to reach the device from the same local network can trigger it without credentials, and a hand-built HTTP request returns operating system commands. Zyxel shipped fixed firmware in June 2026. The break-ins began around 17 August.
How the operator worked
The tooling was a Python script obfuscated with PyArmor, a commercial product. Unwrapped, it named GS1900-24 firmware versions 2.10 to 2.90 as its target and offered command-line switches for other builds. A collector script arrived over TFTP next. Among the victims, 564 were still authenticating with factory defaults.
Acronis already has a name for this operator, or one close to it – Red Heron. That cluster broke into Gitea servers this year using CVE-2026-60004, and its fingerprints appear on WordPress, UniFi OS, Flowise and Proxmox intrusions too.
Three days for federal agencies to act
On September 21 the flaw joined CISA’s Known Exploited Vulnerabilities catalog. Civilian federal agencies have until September 24 to patch it and look for signs of compromise. GreyNoise released some attacker addresses but held one back, citing the risk to victims.
Arctic Wolf is separately reporting live exploitation of CVE-2026-32996, a 7.3-rated local privilege escalation in Veeam Agent for Windows. A local foothold is all it takes to reach SYSTEM. Veeam’s fix arrived in Backup and Replication 13.0.2.29.
