Attackers are actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities catalog.
Tracked as CVE-2026-7273, the vulnerability is a stack-based buffer overflow in the switches’ CGI program. An attacker with no privileges on the local network can exploit the flaw by sending specially crafted HTTP requests, potentially allowing them to execute operating system commands on vulnerable devices.
Zyxel released firmware updates for the vulnerability on June 16 and urged customers to upgrade to the latest versions. The affected models include the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48 and GS1900-48HPv2.
CISA added CVE-2026-7273 to its KEV catalog on September 21 and ordered U.S. federal civilian agencies to address the vulnerability by Thursday under its vulnerability remediation requirements. CISA also encouraged other organizations to prioritize patching the flaw because vulnerabilities listed in the KEV catalog are known to have been exploited in real-world attacks.
Security company GreyNoise reported that it detected exploitation of the vulnerability on September 17. The company said a suspected Chinese-speaking threat actor had targeted Zyxel GS1900 switches around the world and claimed that sensitive data was exfiltrated from 996 switches across 48 countries.
GreyNoise said the activity was part of a broader campaign targeting more than a dozen vulnerabilities in different software and technology products. The company described CVE-2026-7273 as a newly observed exploit affecting GS1900 Smart Managed Switches.
Zyxel networking equipment is frequently deployed by internet service providers, which can make vulnerable devices widely distributed across networks. CISA currently lists multiple Zyxel vulnerabilities that have been exploited in the wild, covering routers, switches, firewalls and NAS products.
Organizations using GS1900 switches should check their firmware versions and install the security updates provided by Zyxel as soon as possible. Devices running affected firmware versions should be treated as potentially exposed until they are patched.



