Skip to main content

CISA orders feds to patch Zyxel flaw exploited for data theft

0
High
Vulnerability
Published: 09/22/2026 (09/22/2026, 08:53:09 UTC)
Source: Bleeping Computer

Description

A high-severity stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches allows unauthenticated attackers on the local network to execute OS commands via crafted HTTP requests. This vulnerability is actively exploited in the wild for data theft. Zyxel released firmware updates to address the issue in June 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch affected devices promptly and added the vulnerability to its Known Exploited Vulnerabilities Catalog. Threat intelligence reports indicate nearly 1,000 devices were compromised globally, with data exfiltration confirmed. The affected devices are widely deployed by internet service providers worldwide.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 09:02:55 UTC

Technical Analysis

CVE-2026-7273 is a stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900 series switches. It enables attackers without local privileges to execute arbitrary OS commands through malicious HTTP requests. Zyxel issued security updates on June 16, 2026, to fix this flaw. CISA has confirmed active exploitation and ordered federal agencies to patch affected devices by a specified deadline. GreyNoise intelligence identified a campaign exploiting this vulnerability, resulting in the compromise and data theft from 996 Zyxel switches across 48 countries. The vulnerability affects multiple GS1900 models with firmware versions at or below specific 2.90 series builds, which Zyxel has patched in subsequent firmware releases.

Potential Impact

Successful exploitation allows unauthenticated attackers on the local network to execute arbitrary operating system commands on vulnerable Zyxel GS1900 switches, leading to potential data theft. Nearly 1,000 devices have been compromised globally, with confirmed exfiltration of sensitive data. This poses significant risks to network security and confidentiality, especially in environments using these switches.

Mitigation Recommendations

Zyxel released official firmware updates on June 16, 2026, that address this vulnerability. Affected users should upgrade to the patched firmware versions immediately to ensure protection. Federal agencies are mandated by CISA's Binding Operational Directive 26-04 to patch affected devices promptly. Organizations are encouraged to prioritize remediation of this vulnerability as it is actively exploited in the wild. No alternative mitigations or workarounds are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.67,"severitySource":"stated","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/","fetched":true,"fetchedAt":"2026-09-22T09:02:46.782Z","wordCount":792}

Threat ID: 6ab24436f7a7c54106f25269

Added to database: 09/22/2026, 09:02:46 UTC

Last enriched: 09/22/2026, 09:02:55 UTC

Last updated: 09/23/2026, 01:41:07 UTC

Views: 28

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses