# CISA orders federal agencies to patch actively exploited Zyxel switch flaw

_Published Tuesday, September 22, 2026 at 6:07 AM EDT · Security · Latest · Tier 1 — Major_

![CISA orders federal agencies to patch actively exploited Zyxel switch flaw — Primary](https://www.bleepstatic.com/content/hl-images/2026/04/08/CISA.jpg)

The U.S. Cybersecurity and Infrastructure Security Agency added a command-execution flaw in Zyxel GS1900 switches to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to secure affected devices by Thursday. CVE-2026-7273 is a stack-based buffer overflow that lets an unauthenticated attacker on the local network send a crafted HTTP request and execute operating-system commands.

Zyxel issued corrected firmware on June 16. GreyNoise reported that a suspected Chinese-speaking actor exploited the flaw to extract sensitive data from 996 switches across 48 countries, although CISA has not released details of the attacks.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/)

---
Canonical: https://techandbusiness.org/newswire/ZdJ1CG2wj_cWIPqm8YhTYy
Published: 2026-09-22T10:07:01.251Z
Story chronology: 2026-09-22T08:53:09.000Z
Retrieved: 2026-09-22T12:11:51.333Z
Publisher: Tech & Business (techandbusiness.org)
