Pages

Monday, September 21, 2026

CISA Adds Zyxel Vulnerability to KEV – Catalog – 9-21-26 

Today, CISA announced that they had added a stack-based buffer overflow vulnerability in the Zyxel GS1900 series switches to their Known Exploitable Vulnerabilities (KEV) catalog. Zyxel reported the vulnerability on June 16th, 2026. The vulnerability was reported to Zyxel by Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from Institute of Software, Chinese Academy of Sciences (ISCAS). 

Today, GreyNoise reported (in an article about a WordPress exploit): 

“In addition to the above findings, GreyNoise discovered the MCA [malicious cyber actor] targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273. As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability, which is also not on [obviously dated before today’s CISA announcement] the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog at the time of publication. The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.” 

CISA has directed federal agencies using the affected Zyxel devices to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [Links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

A compliance date of September 24th, 2026, has been established. 

No comments:

Post a Comment