Cybersecurity

CISA Requires U.S. Federal Agencies to Patch Zyxel Vulnerability Exploited to Steal Data

CISA added CVE-2026-7273 in Zyxel GS1900 switches to its catalog of exploited vulnerabilities and ordered U.S. federal civilian agencies to address it by Thursday. GreyNoise says attackers exploited the vulnerability to compromise 996 switches in 48 countries.

2026-09-22
3 min read
2 views
فريق تحرير certi.news
CISA Requires U.S. Federal Agencies to Patch Zyxel Vulnerability Exploited to Steal Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal civilian executive agencies to secure Zyxel GS1900 switches affected by CVE-2026-7273 before Thursday, after observing its active exploitation in attacks targeting data theft. The agency added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on Monday, making remediation mandatory for entities covered by Binding Operational Directive BOD 26-04.

Vulnerability Allows Remote Command Execution

CVE-2026-7273 results from a stack overflow in CGI software within the switches. An attacker without privileges on the local network can execute system commands by sending specially crafted HTTP requests. Zyxel released security updates to address the issue on June 16, urging customers to upgrade the firmware for optimal protection.

Zyxel has not yet updated its advisory to confirm active exploitation, but GreyNoise said in a report released Monday that it observed the first signs of exploitation on September 17, 2026. The company said a suspected Chinese-speaking threat actor exploited the vulnerability as part of a broader campaign and managed to compromise and extract sensitive data from 996 Zyxel switches in 48 countries.

Affected Models and Versions

  • GS1900-8: Version 2.90(AAHH.1)C0 and earlier; fix 2.90(AAHH.2)C0.
  • GS1900-8HP: Version 2.90(AAHI.1)C0 and earlier; fix 2.90(AAHI.2)C0.
  • GS1900-10HP: Version 2.90(AAZI.1)C0 and earlier; fix 2.90(AAZI.2)C0.
  • GS1900-16: Version 2.90(AAHJ.1)C0 and earlier; fix 2.90(AAHJ.2)C0.
  • GS1900-24, GS1900-24E, and GS1900-24EP: Versions 2.90(AAHL.1)C0, 2.90(AAHK.1)C0, and 2.90(ABTO.1)C0 and earlier, with corresponding fixes 2.90(AAHL.2)C0, 2.90(AAHK.2)C0, and 2.90(ABTO.2)C0.
  • GS1900-24HPv2: Version 2.90(ABTP.1)C0 and earlier; fix 2.90(ABTP.2)C0.
  • GS1900-48: Version 2.90(AAHN.1)C0 and earlier; fix 2.90(AAHN.2)C0.
  • GS1900-48HPv2: Version 2.90(ABTQ.1)C0 and earlier; fix 2.90(ABTQ.2)C0.

Why Does This Matter?

The shift from having an available update to listing the vulnerability in the KEV catalog means that organizations are required to treat it as a confirmed risk, not a theoretical possibility. The mandatory deadline applies directly to U.S. federal civilian executive agencies, but CISA urged all organizations to prioritize KEV vulnerabilities as part of exposure-based risk management.

The warning is especially significant because Zyxel switches may be part of network infrastructure provided by internet service providers as virtual devices, expanding the scope of potentially exposed equipment. CISA has not disclosed details of the attacks, while GreyNoise data points to a global campaign and data extraction from multiple devices; therefore, the nature of the stolen data, the responsible party, and the ultimate target remain open questions.

CISA is currently tracking 13 vulnerabilities in Zyxel devices, including routers, switches, firewalls, and NAS devices, that have previously been exploited or continue to be exploited. Zyxel says more than one million companies use its solutions in 150 markets worldwide.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news