Opens in a new tab

CISA orders federal agencies to patch exploited Zyxel switch flaw by Thursday

  • Home
  • Blog
  • CISA orders federal agencies to patch exploited Zyxel switch flaw by Thursday
Zyxel switch vulnerability highlighted by glowing network server cables

Federal civilian agencies have until Thursday to patch a high-severity vulnerability in Zyxel GS1900 switches that attackers are already using to steal data, giving network operators a clear window to close the same gap on their own equipment before the next wave lands.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog on Monday and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their switches against ongoing attacks within three days, as required by Binding Operational Directive (BOD) 26-04. The flaw stems from a stack-based buffer overflow in the CGI program that lets threat actors without privileges on the local area network execute OS commands through crafted HTTP requests.

What the vulnerability does

CVE-2026-7273 affects the web management interface on Zyxel GS1900 series Smart Managed Switches. Because the buffer overflow sits in the CGI handler, an attacker on the same network can send a specially crafted HTTP request and run commands on the switch’s underlying operating system without holding valid credentials. That turns a routine management feature into a remote entry point for stealing configuration data, rerouting traffic, or pivoting deeper into the network.

Zyxel released firmware updates for the flaw on June 16 and urged customers to upgrade. The company has not yet updated its advisory to confirm active exploitation in the wild, but external evidence from threat intelligence has now made the in-the-wild use a matter of public record.

Which switch models are affected

Ten Zyxel GS1900 models are vulnerable on the firmware versions listed below, and each one has a patched build available from Zyxel:

  • GS1900-8: 2.90(AAHH.1)C0 and earlier, patched in 2.90(AAHH.2)C0
  • GS1900-8HP: 2.90(AAHI.1)C0 and earlier, patched in 2.90(AAHI.2)C0
  • GS1900-10HP: 2.90(AAZI.1)C0 and earlier, patched in 2.90(AAZI.2)C0
  • GS1900-16: 2.90(AAHJ.1)C0 and earlier, patched in 2.90(AAHJ.2)C0
  • GS1900-24: 2.90(AAHL.1)C0 and earlier, patched in 2.90(AAHL.2)C0
  • GS1900-24E: 2.90(AAHK.1)C0 and earlier, patched in 2.90(AAHK.2)C0
  • GS1900-24EP: 2.90(ABTO.1)C0 and earlier, patched in 2.90(ABTO.2)C0
  • GS1900-24HPv2: 2.90(ABTP.1)C0 and earlier, patched in 2.90(ABTP.2)C0
  • GS1900-48: 2.90(AAHN.1)C0 and earlier, patched in 2.90(AAHN.2)C0
  • GS1900-48HPv2: 2.90(ABTQ.1)C0 and earlier, patched in 2.90(ABTQ.2)C0

What attackers have already done

Threat intelligence company GreyNoise reported on Monday that it spotted the first signs of exploitation last Thursday. According to GreyNoise, a suspected Chinese-speaking malicious cyber actor has compromised nearly 1,000 Zyxel GS1900 switches as part of a broader campaign that also targeted more than a dozen other vulnerabilities across a wide range of software and tech products.

GreyNoise stated that the actor successfully exploited and exfiltrated sensitive data from 996 Zyxel switches across 48 countries, making this the first publicly documented case of in-the-wild exploitation of CVE-2026-7273. The campaign’s reach is wide because Zyxel devices are often deployed as default, out-of-the-box equipment by internet service providers handing out new service contracts, which means a single vendor’s switch can sit on customer networks worldwide.

Why CISA added the flaw to the KEV catalog

Adding CVE-2026-7273 to the KEV catalog triggers the binding remediation deadline for federal agencies and signals to private organizations that the vulnerability is an active, confirmed threat rather than a theoretical one. CISA’s standard framing applies here as well: this class of vulnerability is a frequent attack vector and poses significant risks to the federal enterprise, and the agency encourages all organizations, not just FCEB agencies, to prioritize remediation of KEV-listed flaws.

CISA has not released technical details of the attacks abusing CVE-2026-7273, which is consistent with its practice of avoiding early disclosure that could help other attackers reuse the exploit before defenders patch.

Zyxel’s history of targeted bugs

The GS1900 campaign fits a longer pattern. In February, Zyxel warned that it had no plans to patch a pair of actively exploited zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers that were still available for sale online, and instead strongly advised customers to replace those routers with newer products running patched firmware. CISA currently tracks 13 Zyxel vulnerabilities across routers, switches, firewalls, and NAS devices that have been or are still exploited in the wild. Zyxel says more than 1 million businesses use its networking solutions across 150 markets.

What network operators should do now

The practical moves are the same ones CISA is mandating for federal agencies. Inventory every Zyxel GS1900 switch on the network, identify its current firmware version against the table above, and move any device on an affected build to the corresponding patched release as soon as possible. For switches that cannot be patched immediately, restrict management interface access to trusted networks, disable remote administration where feasible, and monitor HTTP logs to the switch’s CGI endpoints for the kind of crafted requests the buffer overflow requires. For end-of-life Zyxel gear that will not receive a patch, plan replacement rather than continued exposure.

FAQ

What is CVE-2026-7273?

CVE-2026-7273 is a stack-based buffer overflow in the CGI program on Zyxel GS1900 series switches. It allows an attacker without LAN privileges to execute operating system commands through a crafted HTTP request to the switch’s management interface.

Why did CISA add CVE-2026-7273 to the KEV catalog?

CISA added the flaw to the Known Exploited Vulnerabilities Catalog because GreyNoise documented active exploitation that compromised 996 Zyxel switches across 48 countries, making it a confirmed in-the-wild threat rather than a theoretical risk.

How long do federal agencies have to patch Zyxel GS1900 switches?

Federal Civilian Executive Branch agencies have until Thursday to secure their Zyxel GS1900 switches against CVE-2026-7273, in line with the three-day remediation window required by Binding Operational Directive (BOD) 26-04.


This article summarizes reporting from bleepingcomputer.com.

← All Articles