MikhbarMIKHBAR
Cybersecurity

CISA Orders Federal Agencies to Patch Exploited Zyxel Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to address an actively exploited vulnerability affecting Zyxel GS1900 series switches. The flaw, identified as CVE-2026-7273, allows for unauthorized command execution.

CISA Orders Federal Agencies to Patch Exploited Zyxel Flaw

Mandatory Remediation for Federal Agencies

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has formally added [CVE-2026-7273](https://nvd.nist.gov/vuln/detail/cve-2026-7273) to its Known Exploited Vulnerabilities (KEV) Catalog. This action follows reports that attackers are targeting a high-severity stack-based buffer overflow vulnerability present within the CGI program of Zyxel GS1900 series switches.

Under the authority of Binding Operational Directive (BOD) 26-04, CISA has ordered Federal Civilian Executive Branch (FCEB) agencies to remediate the vulnerability by this coming Thursday. The agency noted that this specific security flaw enables threat actors without local area network privileges to execute operating system commands through the use of maliciously crafted HTTP requests.

Scope of the Global Exploitation Campaign

While CISA has not yet detailed the specific nature of the attacks, external threat intelligence provides a clearer picture of the campaign’s scale. According to information [said in a Monday report](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation#:~:text=GreyNoise%20discovered%20the%20MCA%20targeted%20ZyXEL%20GS1900%20Smart%20Managed%20Switches%20globally), a suspected Chinese-speaking malicious cyber actor has already compromised nearly 1,000 Zyxel GS1900 switches across 48 different countries.

Researchers at GreyNoise identified the first documented instances of this exploitation occurring as recently as last Thursday. The campaign appears to be part of a broader set of operations targeting a variety of software and technology products, signaling a highly active period for the identified threat actor.

Zyxel Security History and Patch Management

In response to the vulnerability, Zyxel [released security updates](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026) on June 16, 2026, and officially advised all customers to perform firmware upgrades to ensure optimal protection. While the manufacturer has not updated its advisory to reflect current exploitation patterns, CISA’s intervention underscores the urgency of applying these patches.

The company has faced challenges with legacy equipment in the past. Earlier this year, the manufacturer [that it had no plans to patch](https://www.bleepingcomputer.com/news/security/zyxel-wont-patch-newly-exploited-flaws-in-end-of-life-routers/) certain zero-day vulnerabilities in end-of-life routers, instead recommending that customers transition to newer, supported hardware models. Currently, CISA [tracks 13 Zyxel vulnerabilities](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=All&url=&f%5B0%5D=vendor_project%3A855) impacting a range of networking gear, including routers, firewalls, and NAS devices.

Broader Implications for Network Security

CISA noted that this type of buffer overflow vulnerability is a frequent vector used by malicious actors and poses a significant risk to the integrity of federal enterprise networks. While the directive strictly applies to FCEB agencies, CISA encourages all private and public organizations to adopt a proactive, risk-based vulnerability management strategy and prioritize the remediation of items listed within the KEV catalog.

Zyxel hardware remains a common target due to its widespread deployment by internet service providers as default, out-of-the-box equipment for residential and commercial contracts. With over 1 million businesses across 150 markets reportedly utilizing Zyxel solutions, the potential surface for exploitation remains substantial.

Sources