← Back to Feed
CISA orders feds to patch Zyxel flaw exploited for data theft
September 22, 2026 · BleepingComputer · Severity: HIGH
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Key Takeaways
- CISA has ordered federal agencies to patch a Zyxel flaw that is being actively exploited for data theft, adding the vulnerability to the Known Exploited Vulnerabilities catalog.
- The mandatory patching deadline for federal agencies reflects the severity of this Zyxel vulnerability and the confirmed data theft activity observed in the wild.
- Enterprises using Zyxel products should prioritize patching this exploited vulnerability and monitor network traffic for indicators of data exfiltration activity.