Skip to content
Tech News
← Back to articles

CISA orders feds to patch Zyxel flaw exploited for data theft

read original get Zyxel GS1900-24 Managed Switch → more articles
Why This Matters

This story matters because it highlights an actively exploited vulnerability in widely used Zyxel network switches that could allow unauthenticated attackers to execute commands and steal data, putting both government and private networks at risk. CISA's mandate for federal agencies signals the severity of the threat and serves as a warning for all organizations relying on this hardware to patch immediately.

Key Takeaways
Worth a Look

Zyxel GS1900-24 Managed Switch — If you're running an older Zyxel GS1900 switch affected by this actively exploited vulnerability, upgrading to a current-generation managed switch with the latest firmware support is a smart move. The GS1900 series offers easy web-based management and VLAN support, making it a solid choice for securing your local network once properly patched and configured.

See Zyxel GS1900-24 Managed Switch on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

The flaw (tracked as CVE-2026-7273) stems from a stack-based buffer overflow in the CGI program that lets threat actors without privileges on the local area network (LAN) execute OS commands via maliciously crafted HTTP requests.

Zyxel released security updates to address this issue on June 16 and advised customers to upgrade their firmware "for optimal protection."

While Zyxel has yet to update its advisory to confirm active exploitation of this flaw, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog on Monday and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their switches against ongoing attacks by Thursday as mandated by Binding Operational Directive (BOD) 26-04.

"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the cybersecurity agency said.

"While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities."

Affected model Affected version Patch availability GS1900-8 2.90(AAHH.1)C0 and earlier 2.90(AAHH.2)C0 GS1900-8HP 2.90(AAHI.1)C0 and earlier 2.90(AAHI.2)C0 GS1900-10HP 2.90(AAZI.1)C0 and earlier 2.90(AAZI.2)C0 GS1900-16 2.90(AAHJ.1)C0 and earlier 2.90(AAHJ.2)C0 GS1900-24 2.90(AAHL.1)C0 and earlier 2.90(AAHL.2)C0 GS1900-24E 2.90(AAHK.1)C0 and earlier 2.90(AAHK.2)C0 GS1900-24EP 2.90(ABTO.1)C0 and earlier 2.90(ABTO.2)C0 GS1900-24HPv2 2.90(ABTP.1)C0 and earlier 2.90(ABTP.2)C0 GS1900-48 2.90(AAHN.1)C0 and earlier 2.90(AAHN.2)C0 GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier 2.90(ABTQ.2)C0

Although CISA has not released details on attacks abusing CVE-2026-7273, threat intelligence company GreyNoise said in a Monday report that it spotted the first signs of exploitation last Thursday.

According to GreyNoise, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 Zyxel GS1900 switches as part of a campaign that targeted over a dozen other vulnerabilities affecting a wide range of software and tech products.

"GreyNoise discovered the MCA targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273. As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability," it said. "The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries."

... continue reading