CuraSec

Act active

CISA KEV: Zyxel GS1900 flaw actively exploited for data theft

2026-09-22 15:30 UTC · BleepingComputer · read the source ↗ #cisa-kev#zyxel#network-infrastructure
  • Engineer — Act: CISA KEV listing confirms active exploitation of Zyxel GS1900 series switches; if any are in your environment, patch immediately and audit management-plane access logs for signs of unauthorized access.
  • SOC/IR — Act: Active exploitation for data theft means assume-compromise posture on any Zyxel GS1900 devices; hunt for anomalous traffic or config changes originating from or through these switches since KEV listing date.
  • Leader — Plan: Confirm whether Zyxel GS1900 switches appear in network inventory and verify patching is prioritized this week; federal agencies face a hard CISA deadline, but private-sector organizations should treat this as elevated-urgency given confirmed exploitation.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.