Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026

    OpenAI Turned Off the Guardrails | Threat Wire

    September 22, 2026

    Microsoft to retire Microsoft 365 Companion apps in December

    September 22, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»CISA orders feds to patch Zyxel flaw exploited for data theft
    News

    CISA orders feds to patch Zyxel flaw exploited for data theft

    adminBy adminSeptember 22, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    CISA

    ​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

    The flaw (tracked as CVE-2026-7273) stems from a stack-based buffer overflow in the CGI program that lets threat actors without privileges on the local area network (LAN) execute OS commands via maliciously crafted HTTP requests.

    Zyxel released security updates to address this issue on June 16 and advised customers to upgrade their firmware “for optimal protection.”

    While Zyxel has yet to update its advisory to confirm active exploitation of this flaw, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog on Monday and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their switches against ongoing attacks by Thursday as mandated by Binding Operational Directive (BOD) 26-04.

    “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency said.

    “While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.”












    Affected model Affected version Patch availability
    GS1900-8 2.90(AAHH.1)C0 and earlier 2.90(AAHH.2)C0
    GS1900-8HP 2.90(AAHI.1)C0 and earlier 2.90(AAHI.2)C0
    GS1900-10HP 2.90(AAZI.1)C0 and earlier 2.90(AAZI.2)C0
    GS1900-16 2.90(AAHJ.1)C0 and earlier 2.90(AAHJ.2)C0
    GS1900-24 2.90(AAHL.1)C0 and earlier 2.90(AAHL.2)C0
    GS1900-24E 2.90(AAHK.1)C0 and earlier 2.90(AAHK.2)C0
    GS1900-24EP 2.90(ABTO.1)C0 and earlier 2.90(ABTO.2)C0
    GS1900-24HPv2 2.90(ABTP.1)C0 and earlier 2.90(ABTP.2)C0
    GS1900-48 2.90(AAHN.1)C0 and earlier 2.90(AAHN.2)C0
    GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier 2.90(ABTQ.2)C0

    Although CISA has not released details on attacks abusing CVE-2026-7273, threat intelligence company GreyNoise said in a Monday report that it spotted the first signs of exploitation last Thursday.

    According to GreyNoise, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 Zyxel GS1900 switches as part of a campaign that targeted over a dozen other vulnerabilities affecting a wide range of software and tech products.

    “GreyNoise discovered the MCA targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273. As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability,” it said. “The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.”

    ​Zyxel devices are often targeted because many internet service providers worldwide provide them as default, out-of-the-box equipment for new internet service contracts.

    In February, the company warned that it had no plans to patch a pair of actively exploited zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers still available for sale online. Instead, the company “strongly” advised customers to replace routers with newer products whose firmware was already patched.

    CISA currently tracks 13 Zyxel vulnerabilities impacting the company’s routers, switches, firewalls, and NAS devices that have been or are still exploited in the wild.

    Zyxel claims that over 1 million businesses use its networking solutions across 150 markets worldwide.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleOpenAI Turned Off the Guardrails | Threat Wire
    admin
    • Website

    Related Posts

    News

    Microsoft to retire Microsoft 365 Companion apps in December

    September 22, 2026
    News

    WordPress Click2Shell flaw lets hackers execute PHP on the server

    September 21, 2026
    News

    One does not simply defend agentically

    September 21, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026

    OpenAI Turned Off the Guardrails | Threat Wire

    September 22, 2026

    Microsoft to retire Microsoft 365 Companion apps in December

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.