MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-22 · via BleepingComputer

U.S. agencies face Thursday deadline to fix Zyxel switch bug under active attack

Image via BleepingComputer
Image via BleepingComputer

CISA has added a high-severity Zyxel GS1900 switch vulnerability, CVE-2026-7273, to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaw is a stack-based buffer overflow in a CGI program that allows unauthenticated LAN attackers to execute OS commands via crafted HTTP requests. Federal civilian agencies must patch by Thursday, while researchers at GreyNoise have observed a suspected Chinese-speaking actor compromising nearly 1,000 switches.

Expanded Detail

The vulnerability resides in a CGI program within the switch firmware, allowing unauthenticated attackers on the local network to execute operating system commands through specially crafted HTTP requests. Zyxel issued firmware updates on June 16, but the company has not yet publicly confirmed active exploitation. GreyNoise researchers documented the first in-the-wild attacks on September 17, attributing them to a suspected Chinese-speaking actor who compromised 996 switches across 48 countries while also probing a dozen other vulnerabilities in various products. Many internet service providers supply Zyxel switches as default equipment, expanding the potential attack surface. CISA's catalog now lists 13 Zyxel vulnerabilities tied to exploited products, and the company reports over one million businesses use its networking gear across 150 markets.

Context

This incident could affect network administrators and businesses relying on Zyxel GS1900 switches, particularly smaller organizations without dedicated security teams that may miss the patch deadline. Compromised switches could enable data theft, network interception, or lateral movement into broader corporate networks. The scale—nearly 1,000 devices breached globally—suggests attackers may be building a botnet or harvesting credentials for future operations. Federal agencies face immediate consequences if unpatched, but the broader risk may persist for months as unmanaged devices remain exposed, potentially disrupting operations for internet service providers and their customers.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
US agency flags three actively exploited Linux kernel vulnerabilities, including a 14-year-old bug · Cybersecurity
Critical Check Point bug grants unauthenticated root access to management servers · Cybersecurity
WordPress Core CSRF bug enables remote code execution via theme preview · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “CISA orders feds to patch Zyxel flaw exploited for data theft.” Browse more stories.