CISA orders feds to patch actively exploited Zyxel flaw by Thursday
CISA has ordered U.S. federal agencies to patch a critical Zyxel GS1900 series switch vulnerability by Thursday. The flaw is being actively exploited by attackers for data theft.
Intelligence analysis by Gemini 2.5 Flash Lite

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to patch a critical buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series network switches. This vulnerability allows unauthenticated attackers to execute OS commands remotely. The directive mandates patching by Thursday, highlighting the active exploitation of t…
Imagine your home's internet router is like a gatekeeper for your online information. Hackers found a secret way to trick this gatekeeper, called a Zyxel switch, into letting them steal information. The government's security team is telling all its offices to fix these gatekeepers immediately because bad guys are already using this trick.
Analysis
Zyxel GS1900 Series Vulnerability
The vulnerability, identified as CVE-2026-7273, resides within the CGI program of Zyxel's GS1900 series of smart managed switches. It is a stack-based buffer overflow that can be triggered by a specially crafted HTTP request. Crucially, this exploit does not require any prior authentication or local network access, meaning any attacker with internet connectivity could potentially target these devices. The ease of exploitation and the critical nature of network switches, which often manage traffic for entire organizations, make this a significant threat.
CISA's Binding Operational Directive
In response to the active exploitation, CISA has added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion triggers Binding Operational Directive (BOD) 26-04, which mandates that all Federal Civilian Executive Branch (FCEB) agencies must remediate this vulnerability by Thursday. CISA explicitly states that this type of vulnerability is a frequent attack vector and poses significant risks to the federal enterprise. While the directive specifically targets FCEB agencies, CISA strongly encourages all organizations to adopt robust vulnerability management practices and prioritize patching vulnerabilities listed in the KEV Catalog.
Global Exploitation and Data Theft
Threat intelligence from GreyNoise indicates that exploitation of this Zyxel flaw began as early as last Thursday, with a suspected Chinese-speaking threat actor compromising nearly 1,000 GS1900 switches across 48 countries. This campaign is part of a broader effort targeting numerous vulnerabilities in various software and tech products. The attackers have successfully exfiltrated sensitive data from the compromised switches. Zyxel devices are frequently targeted because they are often provided by ISPs as standard equipment, leading to widespread deployment and a large potential attack surface.
Key points
- CISA has identified CVE-2026-7273, a critical vulnerability in Zyxel GS1900 series switches, as actively exploited.
- The flaw allows unauthenticated attackers to execute OS commands via crafted HTTP requests.
- U.S. federal agencies are mandated to patch the vulnerability by Thursday under Binding Operational Directive 26-04.
- Threat intelligence indicates a Chinese-speaking actor has already compromised nearly 1,000 Zyxel switches globally, exfiltrating data.
- CISA urges all organizations to prioritize remediation of vulnerabilities listed in its Known Exploited Vulnerabilities Catalog.
Prompt patching by federal agencies will effectively neutralize the threat posed by CVE-2026-7273, preventing further data theft and securing critical network infrastructure. This swift action by CISA reinforces the importance of proactive vulnerability management across all sectors.
If federal agencies fail to patch the Zyxel vulnerability by the Thursday deadline, attackers could continue to exploit it, leading to widespread data breaches and potential disruption of government operations. The widespread use of these devices also poses a risk to other organizations if they do not follow CISA's recommendation.



