← Back to Feed

CISA orders feds to patch Zyxel flaw exploited for data theft

September 22, 2026 · BleepingComputer · Severity: HIGH

​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Key Takeaways

  • CISA has ordered federal agencies to patch a Zyxel flaw that is being actively exploited for data theft, adding the vulnerability to the Known Exploited Vulnerabilities catalog.
  • The mandatory patching deadline for federal agencies reflects the severity of this Zyxel vulnerability and the confirmed data theft activity observed in the wild.
  • Enterprises using Zyxel products should prioritize patching this exploited vulnerability and monitor network traffic for indicators of data exfiltration activity.
☕ Buy a Coffee