CISA orders feds to patch Zyxel flaw exploited for data theft
CISA added actively exploited Zyxel GS1900 flaw CVE-2026-7273 to KEV, ordering federal agencies to patch by Thursday after ~1,000 switches were compromised.
CISA added CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel GS1900 switches allowing unprivileged LAN attackers to execute OS commands via crafted HTTP requests, to its KEV Catalog and ordered FCEB agencies to patch by Thursday under BOD 26-04; Zyxel shipped fixes on June 16. GreyNoise reported a suspected Chinese-speaking actor exploiting the flaw as a novel vector since mid-September, compromising and exfiltrating data from 996 switches across 48 countries while targeting over a dozen other vulnerabilities. CISA tracks 13 total exploited Zyxel vulnerabilities across routers, switches, firewalls, and NAS devices; affected models span GS1900-8 through GS1900-48HPv2 with firmware 2.90 variants.