SPOJENO AI KEV ✓ EPSS 0.02
CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
Zyxel veřejná správa US CA IT
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-7273 | 8.8 3.1 · Zyxel | KEV ✓ | 0.02 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Tohle CVE jsem vytáhl z širšího textu článku: CVE-2024-40891. Neukazuju u něj proto fakta z katalogů výše, a to preventivně, protože článek se na něj mohl jen odkazovat, třeba jako na starší kauzu.
Jak se o tom psalo 4
-
· BleepingComputer US nadpis události
CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
-
· Cyber Centre Kanada CA
Zyxel security advisory (AV26-603) – Update 1
Serial number: AV26-603Date: June 16, 2026Updated: September 21, 2026 On June 16, 2026, Zyxel published a security advisory to address vulnerabilities in the following products: GS1900 series switches – multiple versions and models Update 1 On September 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the…
-
· CISA KEV US
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability (CVE-2026-7273)
CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog. Affected product: Zyxel GS1900 Series Switches. Remediation due date: 2026-09-24.
-
· CSIRT Itálie (ACN) IT
Rilevata vulnerabilità in prodotti Zyxel
Rilevata una nuova vulnerabilità con gravità “alta”, nei firmware degli switch Zyxel GS1900. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di inviare una richiesta HTTP malevola per eseguire codice arbitrario sui sistemi interessati.