CISA orders feds to patch Zyxel flaw exploited for data theft

A high-severity vulnerability in Zyxel switches has been exploited to steal sensitive data from nearly 1,000 devices worldwide. The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch the flaw immediately, highlighting the significant risks it poses to the federal enterprise.

The vulnerability, tracked as CVE-2026-7273, was first disclosed in June when Zyxel released security updates to address the issue. However, it appears that attackers have been actively exploiting this flaw for weeks, with threat intelligence company GreyNoise spotting the first signs of exploitation last Thursday. According to GreyNoise, a Chinese-speaking malicious cyber actor (MCA) has compromised over 1,000 Zyxel GS1900 switches as part of a larger campaign targeting multiple vulnerabilities in various software and tech products.

The CVE-2026-7273 flaw stems from a stack-based buffer overflow in the CGI program that allows attackers to execute OS commands via maliciously crafted HTTP requests. This type of vulnerability is particularly concerning because it can be exploited by actors without privileges on the local area network (LAN), making it an attractive target for threat actors.

CISA’s decision to add CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog and order federal agencies to patch their switches by Thursday is a clear indication of the agency’s concern about this vulnerability. The cybersecurity agency has also encouraged all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.

Zyxel devices are often targeted because many internet service providers worldwide provide them as default equipment for new internet service contracts. In February, the company warned that it had no plans to patch a pair of zero-day bugs affecting end-of-life routers still available for sale online, instead advising customers to replace their routers with newer products whose firmware was already patched.

The fact that CISA currently tracks 13 Zyxel vulnerabilities impacting various products, including routers, switches, firewalls, and NAS devices, raises concerns about the security posture of organizations relying on these solutions. Zyxel claims that over 1 million businesses use its networking solutions across 150 markets worldwide, making it a significant player in the market.

In practical terms, this incident highlights the importance of regular firmware updates and vulnerability patching. Organizations using Zyxel switches should immediately check if their devices are affected by CVE-2026-7273 and apply the necessary patches to prevent data theft and other potential attacks. Furthermore, companies should adopt a proactive approach to vulnerability management, regularly scanning for known vulnerabilities and prioritizing remediation efforts to minimize the risk of exploitation.


Source: Bleeping Computer — 2026-09-22