
Zyxel GS1900 flaw CVE-2026-7273 exploited, CISA says
CISA added the Zyxel GS1900 flaw CVE-2026-7273 to its exploited-vulnerabilities catalog after GreyNoise reported attacks on 996 switches.
The Zyxel GS1900 switch flaw tracked as CVE-2026-7273 is being exploited in real attacks, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). CISA added the flaw, which affects GS1900 series switches, to its Known Exploited Vulnerabilities (KEV) Catalog on Monday and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their switches by Thursday, as required by Binding Operational Directive (BOD) 26-04. The KEV Catalog is the U.S. government's running list of flaws that attackers are known to be using, and a binding operational directive is an instruction from CISA that federal agencies are obliged to follow. The agency said that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise, and it encouraged all organizations, not only federal agencies, to adopt risk-based vulnerability management and to prioritize fixing the flaws on the KEV Catalog.
CVE-2026-7273 is a high-severity stack-based buffer overflow in the CGI program that runs on the switches. A buffer overflow happens when a program writes more data into a fixed-size block of memory than the block can hold, so the extra data spills into neighbouring memory and can change the way the program behaves. A CGI program is a small piece of software that handles requests to a device's built-in admin pages, the web interface an administrator uses to configure it. According to CISA, the flaw lets an attacker who holds no account and no privileges on the local area network, meaning the network the switch itself sits on, run operating system commands on the device by sending maliciously crafted HTTP requests, which are the ordinary messages a browser or a script sends when it asks a web page for something. In effect, traffic that looks like a routine web request can be turned into instructions the switch carries out on the attacker's behalf.
Zyxel released security updates for the issue on 16 June and advised customers to upgrade their firmware, the built-in software that runs the device, for optimal protection. The affected models and the versions that fix them are:
GS1900-8: 2.90(AAHH.1)C0 and earlier, fixed in 2.90(AAHH.2)C0
GS1900-8HP: 2.90(AAHI.1)C0 and earlier, fixed in 2.90(AAHI.2)C0
GS1900-10HP: 2.90(AAZI.1)C0 and earlier, fixed in 2.90(AAZI.2)C0
GS1900-16: 2.90(AAHJ.1)C0 and earlier, fixed in 2.90(AAHJ.2)C0
GS1900-24: 2.90(AAHL.1)C0 and earlier, fixed in 2.90(AAHL.2)C0
GS1900-24E: 2.90(AAHK.1)C0 and earlier, fixed in 2.90(AAHK.2)C0
GS1900-24EP: 2.90(ABTO.1)C0 and earlier, fixed in 2.90(ABTO.2)C0
GS1900-24HPv2: 2.90(ABTP.1)C0 and earlier, fixed in 2.90(ABTP.2)C0
GS1900-48: 2.90(AAHN.1)C0 and earlier, fixed in 2.90(AAHN.2)C0
GS1900-48HPv2: 2.90(ABTQ.1)C0 and earlier, fixed in 2.90(ABTQ.2)C0
One point of uncertainty is worth stating plainly: Zyxel has not yet updated its own advisory to confirm that the flaw is being exploited in the wild. The evidence of active attacks currently comes from CISA's decision to add CVE-2026-7273 to the KEV Catalog and from a threat intelligence company's research, not from a statement by the manufacturer.
The threat intelligence company GreyNoise said in a report published on Monday that it spotted the first signs of exploitation last Thursday. GreyNoise states that a suspected Chinese-speaking malicious cyber actor compromised nearly 1,000 Zyxel GS1900 switches as part of a campaign that also targeted more than a dozen other vulnerabilities affecting a wide range of software and technology products. In its report, GreyNoise writes that the actor targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273, that as of 17 September 2026 this was the first publicly documented case of exploitation in the wild of this vulnerability, and that the actor successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries. CISA has not released details of the attacks themselves.
The reason this class of device keeps coming up is where it sits. Zyxel gear is often targeted because many internet service providers worldwide hand it to customers as default, out-of-the-box equipment for new internet contracts, which places it at the edge of a large number of small and mid-sized networks. The history matters too. In February, Zyxel warned that it had no plans to patch a pair of actively exploited zero-day bugs affecting end-of-life routers, meaning models the company no longer supports, that were still available for sale online; the two flaws were referred to in the report by the identifier CVE-2024-40891. Instead, the company strongly advised customers to replace those routers with newer products whose firmware was already patched. CISA currently tracks 13 Zyxel vulnerabilities affecting the company's routers, switches, firewalls and NAS (network-attached storage) devices that have been or are still exploited in the wild. Zyxel itself claims that over 1 million businesses use its networking solutions across 150 markets worldwide.
For website owners, businesses and IT teams, the practical question is whether a GS1900 is part of your own network. Switches sit underneath everything else: they carry the traffic between servers, workstations and the internet connection, and a compromised one can hand an intruder a foothold that no amount of application-level security will close. The steps that follow from the source are limited but clear. Zyxel's fix exists and was published on 16 June, so the first move is to establish which firmware version a device is running and whether it matches the patched releases listed above. CISA's own guidance in this case goes beyond federal agencies: it encourages every organization to adopt risk-based vulnerability management, which simply means knowing which systems you run, which flaws affect them and which to fix first. Because the flaw can be reached by someone on the same local network, general good practice of keeping a switch's management interface reachable only from trusted internal networks, and not exposed to the open internet, is worth confirming at the same time. The details in this article are drawn from BleepingComputer's report on the CISA listing and GreyNoise's findings; the exploitation research is GreyNoise's, not ours. Organizations that would rather not track vendor advisories by hand can look at what AEU-I, the group's security-first IT, infrastructure and consulting service, offers for turning patch notices into a routine.
How to Protect Yourself
- Check whether any Zyxel GS1900 switch is used on your home or office network, and if one is, make sure the person who looks after it has installed the fixed firmware version listed for that model.
- If your internet provider supplied the device, call them and ask directly whether it has been updated against CVE-2026-7273.
- Make sure the switch's built-in admin page cannot be reached from the open internet, only from inside your own network.
- Note down the model name and current software version of your network equipment so that the next urgent security notice takes you two minutes to check.
- Check the manufacturer's security notices page once a month, or switch on automatic updates, so that fixes for known flaws do not sit uninstalled.
Vulnerabilities & Fixes
- CVE-2024-40891 Identifier given to a pair of actively exploited bugs in end-of-life Zyxel routers that the company said it did not plan to patch, advising customers to replace the devices instead. View the fix & details →
- CVE-2026-7273 Stack-based buffer overflow in the CGI program of Zyxel GS1900 series switches that lets an attacker on the local network run operating system commands; Zyxel published firmware updates on 16 June. View the fix & details →
Terms Explained
- CISA The U.S. Cybersecurity and Infrastructure Security Agency, the government body that publishes security alerts and instructions for federal agencies.
- CVE A unique reference number given to a publicly known security flaw so that everyone is talking about the same problem.
- KEV Catalog A U.S. government list of security flaws that attackers are known to be actively using right now.
- buffer overflow A bug where a program puts more data into a fixed-size space in memory than fits, so the extra data spills over and changes how the program behaves.
- firmware The built-in software stored inside a piece of hardware that makes the device work.
- local area network The network inside a single home or office, where the devices can talk to each other directly.
- zero-day A security flaw that attackers are already using before, or without, a fix being available.