CISA Directs Federal Agencies to Patch Actively Exploited Zyxel Switch Vulnerability

A high-severity flaw in Zyxel GS1900 series switches is being exploited in the wild for data theft, prompting a mandatory remediation order for US federal agencies.

AI-generated illustration depicting policy for the story: CISA Directs Federal Agencies to Patch Actively Exploited Zyxel Switch Vulnerability

Summary

  • CISA has added a high-severity Zyxel GS1900 series switch vulnerability to its Known Exploited Vulnerabilities catalogue.
  • Attackers are actively exploiting the flaw to conduct data theft.
  • US federal civilian agencies are under a mandatory directive to patch within CISA’s standard remediation window.
  • Organisations outside the federal government should treat the KEV listing as a strong signal to prioritise remediation.
  • No corroborating technical detail beyond the BleepingComputer report is available at this time.

Active Exploitation Confirmed

The US Cybersecurity and Infrastructure Security Agency has confirmed that a high-severity vulnerability affecting Zyxel GS1900 series switches is being actively exploited by attackers. The agency has added the flaw to its Known Exploited Vulnerabilities catalogue, the mechanism CISA uses to formally signal that a weakness has moved from theoretical risk to observed, real-world attack activity.

Data Theft Is the Reported Goal

According to the BleepingComputer report, the exploitation observed is tied to data theft. The GS1900 series are managed gigabit switches commonly deployed in enterprise and small-to-medium business environments, making them a plausible target for adversaries seeking access to network infrastructure or the data traversing it. The precise method of exploitation and the identity of the threat actors involved are not detailed in the available source material.

Federal Agencies Face Mandatory Deadline

CISA’s Binding Operational Directive 22-01 requires all federal civilian executive branch agencies to remediate vulnerabilities listed on the KEV catalogue within defined timeframes. An entry on the catalogue is therefore not advisory for those agencies — it carries legal weight. For private sector and state government organisations, the catalogue carries no mandatory force, but CISA strongly encourages all network owners to treat KEV listings as a prioritisation signal.

What Is Not Yet Known

The source material does not specify the CVE identifier, the precise nature of the underlying vulnerability, patch availability details, or the scope of observed intrusions. CISO teams should consult Zyxel’s official security advisory and CISA’s KEV catalogue directly for the most current technical information, as additional detail may have been published after the time of reporting.

Why it matters

Network switches sit at the heart of enterprise infrastructure — they are trusted, often under-monitored, and rarely subject to the same patch cadence as endpoints or servers. A vulnerability in managed switches that is already being used for data theft represents a meaningful lateral movement and exfiltration risk. If Zyxel GS1900 devices are in your environment, they warrant immediate attention regardless of whether your organisation falls under CISA’s mandate. CISOs should also use this as a prompt to audit the patching posture of network hardware more broadly, a category that frequently lags behind other asset classes.

What to do now

  • Check your asset inventory for Zyxel GS1900 series switches across all network segments.
  • Consult Zyxel’s official security advisories and CISA’s Known Exploited Vulnerabilities catalogue for the specific CVE and available patches.
  • Apply vendor-supplied patches or mitigations within your organisation’s priority window, treating KEV-listed vulnerabilities as high urgency.
  • Review access logs and network telemetry on affected devices for indicators of anomalous activity or unauthorised access.
  • If patching cannot be applied immediately, assess whether compensating controls — such as restricting management interface access — can reduce exposure in the interim.

Sources