Cybersecurity Agency Warns of Widespread Exploitation of Zyxel Flaw, Orders Federal Agencies to Patch
The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a high-severity vulnerability in Zyxel GS1900 series switches that is being actively exploited by attackers. CISA has added the flaw, tracked as CVE-2026-7273, to its Known Exploited Vulnerabilities (KEV) Catalog and ordered federal civilian executive branch agencies to patch their switches by Thursday.
The vulnerability stems from a stack-based buffer overflow in the CGI program that allows threat actors to execute OS commands via maliciously crafted HTTP requests without requiring local privileges on the network. Zyxel released security updates to address this issue back in June, but it appears that many organizations have yet to apply these patches.
CISA is particularly concerned about the potential impact of this vulnerability, citing its frequent use as an attack vector by malicious cyber actors and the significant risks it poses to the federal enterprise. While CISA’s Binding Operational Directive (BOD) 26-04 only applies to federal civilian executive branch agencies, the agency is encouraging all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
The exploitation of CVE-2026-7273 has been linked to a suspected Chinese-speaking malicious cyber actor (MCA) who has compromised nearly 1,000 Zyxel GS1900 switches as part of a broader campaign targeting over a dozen other vulnerabilities affecting various software and tech products. Threat intelligence company GreyNoise reported spotting the first signs of exploitation last Thursday.
Zyxel devices are often targeted because they are frequently provided by internet service providers worldwide as default equipment for new internet service contracts. This makes them a prime target for attackers looking to exploit unpatched vulnerabilities. In fact, CISA currently tracks 13 Zyxel vulnerabilities impacting various products that have been or are still exploited in the wild.
The widespread exploitation of CVE-2026-7273 highlights the need for organizations to prioritize patch management and vulnerability remediation. With over 1 million businesses using Zyxel’s networking solutions across 150 markets worldwide, it is likely that many organizations will be affected by this vulnerability. As CISA emphasizes, adopting risk-based vulnerability management and prioritizing remediation of KEV Catalog vulnerabilities can help mitigate the risks associated with this flaw.
To protect yourself and your organization from this vulnerability, ensure that you have applied the latest security updates for Zyxel GS1900 series switches and review your patch management processes to identify any potential weaknesses. By taking proactive steps to address this vulnerability, you can reduce the risk of a successful cyber attack and maintain the security and integrity of your network.
Source: Bleeping Computer — 2026-09-22