The Exploit Bulletin

Archives
Log in
Subscribe
September 22, 2026

The Exploit Bulletin — Tuesday, September 22, 2026: 2 issues require action

Tuesday, September 22, 2026 — 2 issues require action. If you run none of the software below, you are done.

Affects: Zyxel · WordPress Core, fixed in


1. Unauthenticated stack overflow in Zyxel GS1900 switch web CGI yields OS command execution (CVE-2026-7273)

CISA KEV (due 2026-09-24) · REMOTE CODE EXECUTION · CRITICAL · CVSS 8.8

CISA added CVE-2026-7273 to KEV on 2026-09-21 citing evidence of active exploitation, and teams that leave GS1900 switches on 2.90(*.1)C0 or earlier with reachable web management risk an attacker gaining OS-level control of the network edge.

A stack-based buffer overflow in the CGI program of Zyxel GS1900 series switch firmware lets an unauthenticated attacker who can reach the switch's HTTP management interface execute OS commands with a single crafted request. Zyxel describes the attacker as LAN-based, but any GS1900 whose web management is reachable from untrusted networks or the internet is exposed to full device takeover.

Affected: Zyxel GS1900-8 firmware <= 2.90(AAHH.1)C0; Zyxel GS1900-8HP firmware <= 2.90(AAHI.1)C0; Zyxel GS1900-10HP firmware <= 2.90(AAZI.1)C0; Zyxel GS1900-16 firmware <= 2.90(AAHJ.1)C0; Zyxel GS1900-24 firmware <= 2.90(AAHL.1)C0; Zyxel GS1900-24E firmware <= 2.90(AAHK.1)C0; Zyxel GS1900-24EP firmware <= 2.90(ABTO.1)C0; Zyxel GS1900-24HPv2 firmware <= 2.90(ABTP.1)C0; Zyxel GS1900-48 firmware <= 2.90(AAHN.1)C0; Zyxel GS1900-48HPv2 firmware <= 2.90(ABTQ.1)C0

How to Test: Check the firmware version shown in each GS1900's web management interface: any 2.90(xxxx.1)C0 or earlier build on the listed models is vulnerable, while 2.90(xxxx.2)C0 is fixed. Determine whether the switch's HTTP/HTTPS management interface is reachable from the internet or from untrusted VLANs. Review any available web-server or syslog output from the switch for unexpected or malformed HTTP requests to CGI endpoints, unexplained reboots, or configuration changes you did not make; if compromise is suspected, treat the device as untrusted and re-flash from known-good firmware.

How to Patch: Upgrade each model to the fixed firmware Zyxel released on 2026-06-16: GS1900-8 2.90(AAHH.2)C0, GS1900-8HP 2.90(AAHI.2)C0, GS1900-10HP 2.90(AAZI.2)C0, GS1900-16 2.90(AAHJ.2)C0, GS1900-24 2.90(AAHL.2)C0, GS1900-24E 2.90(AAHK.2)C0, GS1900-24EP 2.90(ABTO.2)C0, GS1900-24HPv2 2.90(ABTP.2)C0, GS1900-48 2.90(AAHN.2)C0, GS1900-48HPv2 2.90(ABTQ.2)C0. Until patched, restrict the web management interface to a trusted management network and remove any internet exposure.

Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · CISA: added to KEV based on evidence of active exploitation · The Hacker News: Zyxel GS1900 flaw under active exploitation · Canadian Centre for Cyber Security AV26-603 Update 1

Full entry with sources →


2. 'Click2Shell' CSRF forces theme install and chains to server-side PHP execution, public PoC (WordPress Core)

UNVERIFIED PUBLIC REPORT · NO CVE · REMOTE CODE EXECUTION · HIGH

A complete PoC and technical write-up became public on 2026-09-21, four days after the 7.1.1 fix shipped, and independent analysis from Patchstack has reproduced the chain; sites still on 7.1.0 or earlier with an admin who clicks a link are now exposed to a weaponizable server-side RCE.

Researcher Paulos Yibelo of pwn.ai published full technical details and a proof-of-concept exploit for 'Click2Shell', a cross-site request forgery flaw in WordPress Core 7.1.0 and earlier. A value from a theme-preview URL is parsed differently by the WordPress.org Themes API and by JavaScript in the administrator's browser, letting an attacker with no account, no nonce and no privileges force a site to install any theme from the official WordPress.org catalog. Because an inactive theme can still execute PHP during a Customizer preview, chaining the forced install with a vulnerable catalog theme yields arbitrary PHP execution on the server — enough to read wp-config.php database credentials, create rogue admins, or plant backdoors. The attack does require a logged-in administrator to visit a crafted link (phishing, or via an existing XSS); Author and Editor accounts cannot trigger it. WordPress fixed the flaw in 7.1.1 (released 2026-09-17) by escaping the theme slug and restricting the jQuery selector to real theme cards. No CVE has been assigned yet; pwn.ai says WordPress plans to add one. No exploitation reports are known at this time.

Affected: WordPress Core 7.1.0 and earlier; fixed in 7.1.1

How to Test: Check your version in Dashboard > Updates or with wp core version; anything at 7.1.0 or below is affected. Check whether DISALLOW_FILE_MODS is set in wp-config.php (grep DISALLOW_FILE_MODS wp-config.php). Indicators of a past attack: unexpected themes in Appearance > Themes or under wp-content/themes/ that no administrator installed, Customizer/theme-preview requests in web server logs referencing theme slugs your team never chose, new or unfamiliar administrator accounts, and modified files under wp-content or changes to wp-config.php.

How to Patch: Apply the WordPress 7.1.1 update via Dashboard > Updates or wp core update, then verify with wp core version. Remove any themes you did not install. As an interim control set define('DISALLOW_FILE_MODS', true); in wp-config.php. Rotate database credentials and salts in wp-config.php if you find evidence of an unexpected theme install.

Evidence: BleepingComputer report · Patchstack analysis of the 7.1.1 fix and DISALLOW_FILE_MODS mitigation · The Hacker News coverage

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Wednesday, September 23, 2026: 4 issues require action Older → The Exploit Bulletin — Monday, September 21, 2026: all clear
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.