Hackers tied to a Chinese-speaking threat actor exploit CVE-2026-7273 in Zyxel GS1900 Smart Managed Switches, compromising nearly 1,000 devices and exfiltrating sensitive information, according to reporting by multiple outlets.
GreyNoise, cited by Help Net Security, says the activity involves 996 switches across 48 countries, with the largest concentrations reported in Italy, the United States, Taiwan, South Korea, and several European countries. SecurityWeek similarly reports that the vulnerability is used to steal sensitive data from close to 1,000 Zyxel switches. The outlets describe the exploitation as part of an ongoing operation that has been occurring since at least August.
While the outlets agree on the actor type, device family, vulnerability identifier, approximate victim count, and data-exfiltration outcome, they focus differently on the scope and geography. Help Net Security provides a more detailed breakdown of affected regions and frames the incident as an unfolding campaign, whereas SecurityWeek summarizes the broader claim of widespread exploitation.