AI & TechCybersecurityNewswireTechnologyWhat's Buzzing

CISA Orders Federal Agencies to Patch Zyxel Data Theft Flaw

▼ Summary

– The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog due to active attacks against Zyxel GS1900 series switches.
– The vulnerability involves a stack-based buffer overflow in the CGI program, allowing unauthenticated attackers to execute OS commands via crafted HTTP requests.
– Zyxel released firmware updates on June 16 to patch the flaw, urging customers to upgrade for optimal protection against these ongoing exploits.
– Threat intelligence firm GreyNoise reported that a suspected Chinese-speaking actor compromised nearly 1,000 switches globally, exfiltrating sensitive data from devices in 48 countries.
– CISA mandated Federal Civilian Executive Branch agencies to secure their switches by Thursday under Binding Operational Directive 26-04, while encouraging broader organizational remediation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent mandate requiring federal agencies to patch a critical security flaw in Zyxel networking equipment. The directive targets CVE-2026-7273, a high-severity vulnerability affecting the Zyxel GS1900 series switches. This flaw allows unauthenticated attackers on the local area network to execute operating system commands by sending maliciously crafted HTTP requests, leveraging a stack-based buffer overflow within the device’s CGI program.

Under the terms of Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies must remediate this threat by Thursday. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, signaling that active exploitation is already underway. While Zyxel released firmware updates on June 16 to address the issue, the manufacturer has not yet updated its public advisory to confirm these specific attacks. However, the urgency of the federal order underscores the immediate danger posed by the bug.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency stated in its announcement.

“While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.”

Global Campaign and Active Exploitation

Although CISA did not provide granular details on the specific mechanics of the ongoing attacks, third-party intelligence confirms widespread abuse. Threat intelligence firm GreyNoise reported detecting the first signs of exploitation last Thursday. According to their analysis, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 devices globally.

“GreyNoise discovered the MCA targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273. As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability,” GreyNoise explained in a report released on Monday. “The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.”

This campaign appears to be part of a broader effort targeting over a dozen other vulnerabilities across various software and hardware products. The scope of the breach highlights the severe consequences of leaving such infrastructure unpatched, as attackers were able to extract sensitive information from a vast number of endpoints.

Affected Hardware and Patch Requirements

The vulnerability impacts multiple models within the GS1900 lineup, including the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2. Devices running version 2.90(AAHH.1)C0 or earlier are particularly vulnerable, along with their respective variants such as AAHI, AAZI, AAHJ, AAHL, AAHK, ABTO, ABTP, AAHN, and ABTQ.

To secure their networks, administrators must upgrade to the following patched versions:

  • GS1900-8: 2.90(AAHH.2)C0
  • GS1900-8HP: 2.90(AAHI.2)C0
  • GS1900-10HP: 2.90(AAZI.2)C0
  • GS1900-16: 2.90(AAHJ.2)C0
  • GS1900-24: 2.90(AAHL.2)C0
  • GS1900-24E: 2.90(AAHK.2)C0
  • GS1900-24EP: 2.90(ABTO.2)C0
  • GS1900-24HPv2: 2.90(ABTP.2)C0
  • GS1900-48: 2.90(AAHN.2)C0
  • GS1900-48HPv2: 2.90(ABTQ.2)C0

Zyxel devices are frequently found in enterprise environments because many internet service providers worldwide supply them as default equipment for new contracts. This ubiquity makes them a prime target for large-scale scanning and exploitation campaigns.

Broader Security Context

This incident adds to a growing list of security concerns regarding Zyxel products. In February, the company announced it would not patch two actively exploited zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers that were still being sold online. Instead, Zyxel advised customers to replace these older units with newer models that have received firmware updates.

Currently, CISA tracks 13 Zyxel vulnerabilities impacting routers, switches, firewalls, and NAS devices that have been or are currently exploited in the wild. With Zyxel claiming that over 1 million businesses rely on its networking solutions across 150 markets, the pressure on organizations to implement robust vulnerability management practices has never been higher.

(Source: BleepingComputer)

Topics

vulnerability exploitation 95% Regulatory Compliance 85% network security 80% cyber threat intelligence 75% patch management 70%
Show More