CISA Orders Federal Agencies to Patch Exploited Zyxel Switch Flaw
Share
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal civilian agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches following reports of active exploitation and data theft.
The flaw, tracked as CVE-2026-7273, is a stack-based buffer overflow within the device’s CGI program. This vulnerability allows threat actors without local area network (LAN) privileges to execute operating system commands by sending specially crafted HTTP requests.
Active Exploitation and Data Exfiltration
While Zyxel released security updates for the issue in June, threat intelligence firm GreyNoise reported discovering the first signs of active exploitation in mid-September 2026. According to GreyNoise, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 Zyxel GS1900 switches across 48 countries.
The research indicates that the attacker successfully exfiltrated sensitive data from 996 affected switches as part of a broader campaign targeting multiple software vulnerabilities.
CISA Mandate for Federal Agencies
In response to the ongoing attacks, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to secure their switches against the flaw by Thursday.
CISA noted that this type of vulnerability represents a frequent attack vector and poses significant risks to federal enterprises. Although the mandate applies specifically to FCEB agencies, the agency has encouraged all organisations to adopt risk-based vulnerability management and prioritise the remediation of vulnerabilities listed in the KEV Catalog.
Affected Hardware and Remediation
The vulnerability impacts several models within the GS1900 series, including the GS1900-8, GS1900-16, GS1900-24, and GS1900-48, along with various high-power (HP) and enhanced (E/EP) versions. Users should verify their current firmware versions against Zyxel’s security advisories to ensure they have applied the necessary updates.
Zyxel devices are frequently targeted by malicious actors because they are commonly deployed as default, out-of-the-box equipment by internet service providers (ISPs) globally. The company is currently tracking 13 different vulnerabilities affecting its routers, switches, firewalls, and NAS devices that have seen real-world exploitation.




Leave a Reply