CISA orders feds to patch Zyxel flaw exploited for data theft
A high-severity stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches allows unauthenticated attackers on the local network to execute OS commands via crafted HTTP requests. This vulnerability is actively exploited in the wild for data theft. Zyxel released firmware updates to address the issue in June 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch affected devices promptly and added the vulnerability to its Known Exploited Vulnerabilities Catalog. Threat intelligence reports indicate nearly 1,000 devices were compromised globally, with data exfiltration confirmed. The affected devices are widely deployed by internet service providers worldwide.
AI Analysis
Technical Summary
CVE-2026-7273 is a stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900 series switches. It enables attackers without local privileges to execute arbitrary OS commands through malicious HTTP requests. Zyxel issued security updates on June 16, 2026, to fix this flaw. CISA has confirmed active exploitation and ordered federal agencies to patch affected devices by a specified deadline. GreyNoise intelligence identified a campaign exploiting this vulnerability, resulting in the compromise and data theft from 996 Zyxel switches across 48 countries. The vulnerability affects multiple GS1900 models with firmware versions at or below specific 2.90 series builds, which Zyxel has patched in subsequent firmware releases.
Potential Impact
Successful exploitation allows unauthenticated attackers on the local network to execute arbitrary operating system commands on vulnerable Zyxel GS1900 switches, leading to potential data theft. Nearly 1,000 devices have been compromised globally, with confirmed exfiltration of sensitive data. This poses significant risks to network security and confidentiality, especially in environments using these switches.
Mitigation Recommendations
Zyxel released official firmware updates on June 16, 2026, that address this vulnerability. Affected users should upgrade to the patched firmware versions immediately to ensure protection. Federal agencies are mandated by CISA's Binding Operational Directive 26-04 to patch affected devices promptly. Organizations are encouraged to prioritize remediation of this vulnerability as it is actively exploited in the wild. No alternative mitigations or workarounds are specified.
CISA orders feds to patch Zyxel flaw exploited for data theft
Description
A high-severity stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches allows unauthenticated attackers on the local network to execute OS commands via crafted HTTP requests. This vulnerability is actively exploited in the wild for data theft. Zyxel released firmware updates to address the issue in June 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch affected devices promptly and added the vulnerability to its Known Exploited Vulnerabilities Catalog. Threat intelligence reports indicate nearly 1,000 devices were compromised globally, with data exfiltration confirmed. The affected devices are widely deployed by internet service providers worldwide.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-7273 is a stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900 series switches. It enables attackers without local privileges to execute arbitrary OS commands through malicious HTTP requests. Zyxel issued security updates on June 16, 2026, to fix this flaw. CISA has confirmed active exploitation and ordered federal agencies to patch affected devices by a specified deadline. GreyNoise intelligence identified a campaign exploiting this vulnerability, resulting in the compromise and data theft from 996 Zyxel switches across 48 countries. The vulnerability affects multiple GS1900 models with firmware versions at or below specific 2.90 series builds, which Zyxel has patched in subsequent firmware releases.
Potential Impact
Successful exploitation allows unauthenticated attackers on the local network to execute arbitrary operating system commands on vulnerable Zyxel GS1900 switches, leading to potential data theft. Nearly 1,000 devices have been compromised globally, with confirmed exfiltration of sensitive data. This poses significant risks to network security and confidentiality, especially in environments using these switches.
Mitigation Recommendations
Zyxel released official firmware updates on June 16, 2026, that address this vulnerability. Affected users should upgrade to the patched firmware versions immediately to ensure protection. Federal agencies are mandated by CISA's Binding Operational Directive 26-04 to patch affected devices promptly. Organizations are encouraged to prioritize remediation of this vulnerability as it is actively exploited in the wild. No alternative mitigations or workarounds are specified.
Technical Details
- Classification
- {"confidence":0.67,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/","fetched":true,"fetchedAt":"2026-09-22T09:02:46.782Z","wordCount":792}
Threat ID: 6ab24436f7a7c54106f25269
Added to database: 09/22/2026, 09:02:46 UTC
Last enriched: 09/22/2026, 09:02:55 UTC
Last updated: 09/23/2026, 01:41:07 UTC
Views: 28
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.