CISA Orders Federal Patch for Zyxel Flaw

CISA mandates urgent patches for Zyxel switches after attackers stole data from nearly 1,000 devices across 48 countries.
Key points
- CISA ordered federal agencies to patch Zyxel GS1900 switches by Thursday due to active exploitation.
- Attackers stole data from nearly 1,000 Zyxel switches across 48 countries using a buffer overflow flaw.
- Zyxel released a fix on June 16, but CISA warns the vulnerability remains a high-risk attack vector.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a critical vulnerability in Zyxel GS1900 series switches by this Thursday. The agency added the flaw, identified as CVE-2026-7273, to its Known Exploited Vulnerabilities catalog after confirming that attackers are actively using it to steal data.
This is not a theoretical risk. Threat intelligence firm GreyNoise reports that a suspected Chinese-speaking cyber actor has compromised nearly 1,000 of these switches across 48 countries. The attackers exploited a stack-based buffer overflow to execute unauthorized commands, allowing them to exfiltrate sensitive information from devices that were left unpatched.
The vulnerability allows remote command execution
The flaw exists in the CGI program used for web-based management of the switches. As reported by BleepingComputer, an attacker does not need administrative credentials to exploit this issue. By sending specially crafted HTTP requests, a threat actor can run operating system commands on the device. This effectively gives the attacker full control over the switch, enabling them to read data or alter network configurations.
Zyxel released firmware updates to fix this issue on June 16. However, many organizations may not have applied these patches immediately. The trade-off for users who delayed updates is now clear: their networks have been exposed to active exploitation. CISA notes that this type of vulnerability is a frequent attack vector for malicious actors, posing significant risks to any network where these devices are present.
Federal agencies face strict patch deadlines
Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies are required to remediate vulnerabilities in the KEV catalog within strict timeframes. In this case, they must secure their switches by Thursday. While this mandate applies only to federal agencies, CISA strongly encourages all private organizations to prioritize this patch. The agency advises organizations to adopt risk-based vulnerability management to ensure critical fixes are applied promptly.
The urgency stems from the scale of the ongoing attacks. GreyNoise identified the first signs of exploitation last Thursday, marking the first publicly documented case of this specific vulnerability being used in the wild. The campaign targeted a wide range of software and tech products, indicating a broader effort to compromise network infrastructure.
Zyxel devices remain a frequent target
Zyxel hardware is often the default equipment provided by internet service providers worldwide. This ubiquity makes it an attractive target for attackers seeking broad access to corporate and residential networks. The company claims over one million businesses use its networking solutions across 150 markets, amplifying the potential impact of unpatched flaws.
This incident adds to a growing list of security concerns for Zyxel products. CISA currently tracks 13 Zyxel vulnerabilities that have been exploited in the wild. In February, the company warned that it had no plans to patch certain zero-day bugs in end-of-life routers, advising customers to replace them instead. For users of the GS1900 series, the catch is clear: if you have not applied the June 16 update, your device is likely already compromised or at immediate risk.






