TTO-2026-0922-152 · September 22, 2026 Active ExploitationNation-State

China-Linked APT Chains WordPress and Zyxel Flaws to Steal Government Data — CISA Orders Federal Zyxel Patch

zyxel.comChina-linked APTCVE-2026-27662 Zyxel DSL CPE CVSS 9.8WordPress plugin chainingGovernment and critical infrastructure targetsCISA KEV October 3 deadlineVolexity and CISA attribution

Summary

Volexity and CISA have published coordinated research documenting a China-linked advanced persistent threat campaign that chains a critical vulnerability in Zyxel DSL CPE devices with WordPress plugin flaws to establish persistent access to government and critical infrastructure networks and exfiltrate data. The Zyxel vulnerability, CVE-2026-27662, carries a CVSS score of 9.8 and allows unauthenticated command injection on exposed Zyxel DSL CPE devices. CISA has added CVE-2026-27662 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch or disconnect affected Zyxel devices by October 3, 2026. The campaign has been active since at least early 2026 and has affected government organizations across Southeast Asia, Europe, and the United States.

Timeline

DateEvent
Early 2026China-linked APT begins campaign chaining Zyxel CVE-2026-27662 with WordPress plugin flaws against government targets
September 2026Volexity completes investigation and coordinates disclosure with CISA; campaign attributed to China-linked threat actor
Sep 21, 2026CISA adds CVE-2026-27662 to KEV catalog; orders federal agencies to patch or disconnect affected Zyxel devices by October 3, 2026
Sep 22, 2026BleepingComputer and CybersecurityNews publish full campaign details; TTO-2026-0922-152 published

What Happened

CVE-2026-27662 is an unauthenticated command injection vulnerability in Zyxel DSL CPE devices — the routers and modems installed at government offices and facilities to provide internet connectivity. An attacker with network access to the device’s management interface can send a crafted request that injects operating system commands, achieving root execution on the CPE device without any authentication. Because CPE devices sit at the network perimeter and control traffic flowing in and out of a facility, a compromised CPE device gives an attacker persistent visibility into all network traffic and a pivot point into internal systems.

The China-linked APT used CVE-2026-27662 for initial access and persistence at the network edge, then pivoted inward to web-facing systems. In facilities where WordPress sites were part of the internal or public-facing infrastructure, the group exploited vulnerabilities in WordPress plugins — including authentication bypass and file upload flaws — to establish additional footholds and move laterally. The dual-path intrusion chain meant that patching one vector without the other left the attacker with retained access.

Volexity’s investigation found evidence of data exfiltration targeting personnel records, internal communications, network configuration documentation, and files related to government operations. The campaign’s targeting pattern is consistent with Chinese state-sponsored intelligence collection priorities. CISA’s October 3 deadline is the most urgent remediation action: federal agencies should treat any Zyxel CPE running vulnerable firmware as potentially compromised and conduct forensic triage in addition to patching.

Domain Intelligence

zyxel.com — 62.22

zyxel.com scores in the low-trust range at 62.22. Zyxel is the vendor of the affected DSL CPE devices. CVE-2026-27662 has been patched in Zyxel firmware updates; affected organizations should verify firmware versions and apply available patches immediately alongside the CISA October 3 deadline.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 22, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026