U.S. agencies face Thursday deadline to fix Zyxel switch bug under active attack

CISA has added a high-severity Zyxel GS1900 switch vulnerability, CVE-2026-7273, to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaw is a stack-based buffer overflow in a CGI program that allows unauthenticated LAN attackers to execute OS commands via crafted HTTP requests. Federal civilian agencies must patch by Thursday, while researchers at GreyNoise have observed a suspected Chinese-speaking actor compromising nearly 1,000 switches.
The vulnerability resides in a CGI program within the switch firmware, allowing unauthenticated attackers on the local network to execute operating system commands through specially crafted HTTP requests. Zyxel issued firmware updates on June 16, but the company has not yet publicly confirmed active exploitation. GreyNoise researchers documented the first in-the-wild attacks on September 17, attributing them to a suspected Chinese-speaking actor who compromised 996 switches across 48 countries while also probing a dozen other vulnerabilities in various products. Many internet service providers supply Zyxel switches as default equipment, expanding the potential attack surface. CISA's catalog now lists 13 Zyxel vulnerabilities tied to exploited products, and the company reports over one million businesses use its networking gear across 150 markets.
This incident could affect network administrators and businesses relying on Zyxel GS1900 switches, particularly smaller organizations without dedicated security teams that may miss the patch deadline. Compromised switches could enable data theft, network interception, or lateral movement into broader corporate networks. The scale—nearly 1,000 devices breached globally—suggests attackers may be building a botnet or harvesting credentials for future operations. Federal agencies face immediate consequences if unpatched, but the broader risk may persist for months as unmanaged devices remain exposed, potentially disrupting operations for internet service providers and their customers.