{"id":257330,"date":"2026-09-23T12:12:20","date_gmt":"2026-09-23T09:12:20","guid":{"rendered":"https:\/\/digitrendz.blog\/z\/?p=257330"},"modified":"2026-09-23T12:12:20","modified_gmt":"2026-09-23T09:12:20","slug":"cisa-orders-federal-agencies-to-patch-zyxel-data-theft-flaw","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/257330\/cisa-orders-federal-agencies-to-patch-zyxel-data-theft-flaw\/","title":{"rendered":"CISA Orders Federal Agencies to Patch Zyxel Data Theft Flaw"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog due to active attacks against Zyxel GS1900 series switches.<br>&#8211; The vulnerability involves a stack-based buffer overflow in the CGI program, allowing unauthenticated attackers to execute OS commands via crafted HTTP requests.<br>&#8211; Zyxel released firmware updates on June 16 to patch the flaw, urging customers to upgrade for optimal protection against these ongoing exploits.<br>&#8211; Threat intelligence firm GreyNoise reported that a suspected Chinese-speaking actor compromised nearly 1,000 switches globally, exfiltrating sensitive data from devices in 48 countries.<br>&#8211; CISA mandated Federal Civilian Executive Branch agencies to secure their switches by Thursday under Binding Operational Directive 26-04, while encouraging broader organizational remediation.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">T<\/mark>he <a href=\"https:\/\/digitrendz.blog\/z\/entity\/u-s-cybersecurity-and-infrastructure-security-agency\/\" class=\"acp-entity-link\" data-entity-id=\"54497\" data-entity-category=\"Organization\" title=\"Learn more about U.S. Cybersecurity and Infrastructure Security Agency\" target=\"_blank\" rel=\"noopener noreferrer\">U.S. Cybersecurity and Infrastructure Security Agency<\/a> (CISA) has issued an urgent mandate requiring federal agencies to patch a critical security flaw in Zyxel networking equipment. The directive targets <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/cve-2026-7273\/\" class=\"acp-entity-link\" data-entity-id=\"300798\" data-entity-category=\"Event\" title=\"Learn more about CVE-2026-7273\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-7273<\/a><\/strong>, a high-severity vulnerability affecting the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/zyxel-gs1900-series-switches\/\" class=\"acp-entity-link\" data-entity-id=\"300797\" data-entity-category=\"product\" title=\"Learn more about Zyxel GS1900 series switches\" target=\"_blank\" rel=\"noopener noreferrer\">Zyxel GS1900 series switches<\/a><\/strong>. This flaw allows unauthenticated attackers on the local area network to execute operating system commands by sending maliciously crafted HTTP requests, leveraging a <a href=\"https:\/\/digitrendz.blog\/z\/entity\/stack-based-buffer-overflow\/\" class=\"acp-entity-link\" data-entity-id=\"300800\" data-entity-category=\"Technology\" title=\"Learn more about stack-based buffer overflow\" target=\"_blank\" rel=\"noopener noreferrer\">stack-based buffer overflow<\/a> within the device&#8217;s <a href=\"https:\/\/digitrendz.blog\/z\/entity\/cgi-program\/\" class=\"acp-entity-link\" data-entity-id=\"300799\" data-entity-category=\"Technology\" title=\"Learn more about CGI program\" target=\"_blank\" rel=\"noopener noreferrer\">CGI program<\/a>.<\/p>\n\n<p class=\"wp-block-paragraph\">Under the terms of <strong>Binding Operational Directive (BOD) 26-04<\/strong>, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/federal-civilian-executive-branch\/\" class=\"acp-entity-link\" data-entity-id=\"117375\" data-entity-category=\"Organization\" title=\"Learn more about Federal Civilian Executive Branch\" target=\"_blank\" rel=\"noopener noreferrer\">Federal Civilian Executive Branch<\/a> agencies must remediate this threat by Thursday. <a href=\"https:\/\/digitrendz.blog\/z\/entity\/cisa\/\" class=\"acp-entity-link\" data-entity-id=\"21358\" data-entity-category=\"Organization\" title=\"Learn more about CISA\" target=\"_blank\" rel=\"noopener noreferrer\">CISA<\/a> added the vulnerability to its <strong>Known Exploited Vulnerabilities (KEV) Catalog<\/strong> on Monday, signaling that active exploitation is already underway. While Zyxel released firmware updates on June 16 to address the issue, the manufacturer has not yet updated its public advisory to confirm these specific attacks. However, the urgency of the federal order underscores the immediate danger posed by the bug.<\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,&#8221; the cybersecurity agency stated in its announcement.<\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;While <a href=\"https:\/\/digitrendz.blog\/z\/entity\/bod-26-04\/\" class=\"acp-entity-link\" data-entity-id=\"271002\" data-entity-category=\"law\" title=\"Learn more about BOD 26-04\" target=\"_blank\" rel=\"noopener noreferrer\">BOD 26-04<\/a> applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.&#8221;<\/p>\n\n<h2 class=\"wp-block-heading\">Global Campaign and Active Exploitation<\/h2>\n\n<p class=\"wp-block-paragraph\">Although CISA did not provide granular details on the specific mechanics of the ongoing attacks, third-party intelligence confirms widespread abuse. Threat intelligence firm <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/greynoise\/\" class=\"acp-entity-link\" data-entity-id=\"53052\" data-entity-category=\"Organization\" title=\"Learn more about GreyNoise\" target=\"_blank\" rel=\"noopener noreferrer\">GreyNoise<\/a><\/strong> reported detecting the first signs of exploitation last Thursday. According to their analysis, a suspected <a href=\"https:\/\/digitrendz.blog\/z\/entity\/chinese-speaking-malicious-cyber-actor\/\" class=\"acp-entity-link\" data-entity-id=\"300801\" data-entity-category=\"Person\" title=\"Learn more about Chinese-speaking malicious cyber actor\" target=\"_blank\" rel=\"noopener noreferrer\">Chinese-speaking malicious cyber actor<\/a> (MCA) has compromised nearly 1,000 devices globally.<\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;GreyNoise discovered the MCA targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273. As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability,&#8221; GreyNoise explained in a report released on Monday. &#8220;The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.&#8221;<\/p>\n\n<p class=\"wp-block-paragraph\">This campaign appears to be part of a broader effort targeting over a dozen other vulnerabilities across various software and hardware products. The scope of the breach highlights the severe consequences of leaving such infrastructure unpatched, as attackers were able to extract sensitive information from a vast number of endpoints.<\/p>\n\n<h2 class=\"wp-block-heading\">Affected Hardware and Patch Requirements<\/h2>\n\n<p class=\"wp-block-paragraph\">The vulnerability impacts multiple models within the GS1900 lineup, including the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2. Devices running version <strong>2.90(AAHH.1)C0<\/strong> or earlier are particularly vulnerable, along with their respective variants such as AAHI, AAZI, AAHJ, AAHL, AAHK, ABTO, ABTP, AAHN, and ABTQ.<\/p>\n\n<p class=\"wp-block-paragraph\">To secure their networks, administrators must upgrade to the following patched versions:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>GS1900-8: 2.90(AAHH.2)C0<\/li>\n\n<li>GS1900-8HP: 2.90(AAHI.2)C0<\/li>\n<!-- \/wp:post-content -->\n<li>GS1900-10HP: 2.90(AAZI.2)C0<\/li>\n<!-- \/wp:list-item -->\n<li>GS1900-16: 2.90(AAHJ.2)C0<\/li>\n<!-- \/wp:list-item -->\n<li>GS1900-24: 2.90(AAHL.2)C0<\/li>\n<!-- \/wp:list-item -->\n<li>GS1900-24E: 2.90(AAHK.2)C0<\/li>\n<!-- \/wp:list-item -->\n<li>GS1900-24EP: 2.90(ABTO.2)C0<\/li>\n<!-- \/wp:list-item -->\n<li>GS1900-24HPv2: 2.90(ABTP.2)C0<\/li>\n<!-- \/wp:list-item -->\n<li>GS1900-48: 2.90(AAHN.2)C0<\/li>\n<!-- \/wp:list-item -->\n<li>GS1900-48HPv2: 2.90(ABTQ.2)C0<\/li>\n<!-- \/wp:list-item -->\n<\/ul>\n<!-- \/wp:list -->\n<!-- wp:paragraph -->\n\n<p>Zyxel devices are frequently found in enterprise environments because many internet service providers worldwide supply them as default equipment for new contracts. This ubiquity makes them a prime target for large-scale scanning and exploitation campaigns.<\/p>\n\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading {\"level\":2} -->\n<h2>Broader Security Context<\/h2>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n\n<p>This incident adds to a growing list of security concerns regarding Zyxel products. In February, the company announced it would not patch two actively exploited zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers that were still being sold online. Instead, Zyxel advised customers to replace these older units with newer models that have received firmware updates.<\/p>\n\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n\n<p>Currently, CISA tracks <strong>13 Zyxel vulnerabilities<\/strong> impacting routers, switches, firewalls, and NAS devices that have been or are currently exploited in the wild. With Zyxel claiming that over <strong>1 million businesses<\/strong> rely on its networking solutions across 150 markets, the pressure on organizations to implement robust vulnerability management practices has never been higher.<\/p>\n\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<em>(Source: <a href='https:\/\/bleepingcomputer.com\/news\/security\/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday\/' target='_blank'>BleepingComputer<\/a>)<\/em>\n<!-- \/wp:paragraph -->","protected":false},"excerpt":{"rendered":"<p>CISA has issued an urgent mandate requiring federal agencies to patch CVE-2026-7273, a critical vulnerability in Zyxel GS1900 switches that allows unauthenticated command execution. Active exploitation of this flaw is underway globally, with threat intelligence indicating a malicious actor compro&#8230;<\/p>\n","protected":false},"author":1,"featured_media":257329,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,3297,3327,3254,497],"tags":[257779,257780,257781,257778],"entities":[226514,257784,257786,14622,257783,82702,36418,257785,37392,257782],"class_list":["post-257330","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-cybersecurity","category-newswire","category-technology","category-trending-news","tag-bod-26-04","tag-cgi-program","tag-cve-2026-7273","tag-greynoise","entity-bod-26-04","entity-cgi-program","entity-chinese-speaking-malicious-cyber-actor","entity-cisa","entity-cve-2026-7273","entity-federal-civilian-executive-branch","entity-greynoise","entity-stack-based-buffer-overflow","entity-u-s-cybersecurity-and-infrastructure-security-agency","entity-zyxel-gs1900-series-switches"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=257330"}],"version-history":[{"count":2,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257330\/revisions"}],"predecessor-version":[{"id":257332,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257330\/revisions\/257332"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/257329"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=257330"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=257330"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=257330"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=257330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}