CISA orders feds to patch Zyxel flaw exploited for data theft
CISA added actively exploited Zyxel GS1900 flaw CVE-2026-7273 to KEV, ordering federal agencies to patch by Thursday after ~1,000 switches were compromised.
CISA added CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel GS1900 switches allowing unprivileged LAN attackers to execute OS commands via crafted HTTP requests, to its KEV Catalog and ordered FCEB agencies to patch by Thursday under BOD 26-04; Zyxel shipped fixes on June 16. GreyNoise reported a suspected Chinese-speaking actor exploiting the flaw as a novel vector since mid-September, compromising and exfiltrating data from 996 switches across 48 countries while targeting over a dozen other vulnerabilities. CISA tracks 13 total exploited Zyxel vulnerabilities across routers, switches, firewalls, and NAS devices; affected models span GS1900-8 through GS1900-48HPv2 with firmware 2.90 variants.
- CVE-2026-7273 KEV addition; FCEB patch deadline Thursday under BOD 26-04
- GreyNoise: first in-the-wild exploitation documented September 17, 2026
- Suspected Chinese-speaking actor exfiltrated data from 996 switches in 48 countries
- Unprivileged LAN attackers can execute OS commands via crafted HTTP requests
- Patches available since June 16 across ten GS1900 models
Vulnerabilities mentionedAll →
- CVE-2024-408918.822%Post-Authentication OS Command Injection in Zyxel DSL CPE Devicespublished · Zyxel DSL CPE Devices (multiple models) KEV
Full article515 words · extracted from bleepingcomputer.com · click to collapse

Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
The flaw (tracked as CVE-2026-7273) stems from a stack-based buffer overflow in the CGI program that lets threat actors without privileges on the local area network (LAN) execute OS commands via maliciously crafted HTTP requests.
Zyxel released security updates to address this issue on June 16 and advised customers to upgrade their firmware "for optimal protection."
While Zyxel has yet to update its advisory to confirm active exploitation of this flaw, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog on Monday and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their switches against ongoing attacks by Thursday as mandated by Binding Operational Directive (BOD) 26-04.
"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the cybersecurity agency said.
"While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities."
| Affected model | Affected version | Patch availability |
|---|---|---|
| GS1900-8 | 2.90(AAHH.1)C0 and earlier | 2.90(AAHH.2)C0 |
| GS1900-8HP | 2.90(AAHI.1)C0 and earlier | 2.90(AAHI.2)C0 |
| GS1900-10HP | 2.90(AAZI.1)C0 and earlier | 2.90(AAZI.2)C0 |
| GS1900-16 | 2.90(AAHJ.1)C0 and earlier | 2.90(AAHJ.2)C0 |
| GS1900-24 | 2.90(AAHL.1)C0 and earlier | 2.90(AAHL.2)C0 |
| GS1900-24E | 2.90(AAHK.1)C0 and earlier | 2.90(AAHK.2)C0 |
| GS1900-24EP | 2.90(ABTO.1)C0 and earlier | 2.90(ABTO.2)C0 |
| GS1900-24HPv2 | 2.90(ABTP.1)C0 and earlier | 2.90(ABTP.2)C0 |
| GS1900-48 | 2.90(AAHN.1)C0 and earlier | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | 2.90(ABTQ.1)C0 and earlier | 2.90(ABTQ.2)C0 |
Although CISA has not released details on attacks abusing CVE-2026-7273, threat intelligence company GreyNoise said in a Monday report that it spotted the first signs of exploitation last Thursday.
According to GreyNoise, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 Zyxel GS1900 switches as part of a campaign that targeted over a dozen other vulnerabilities affecting a wide range of software and tech products.
"GreyNoise discovered the MCA targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273. As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability," it said. "The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries."
Zyxel devices are often targeted because many internet service providers worldwide provide them as default, out-of-the-box equipment for new internet service contracts.
In February, the company warned that it had no plans to patch a pair of actively exploited zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers still available for sale online. Instead, the company "strongly" advised customers to replace routers with newer products whose firmware was already patched.
CISA currently tracks 13 Zyxel vulnerabilities impacting the company's routers, switches, firewalls, and NAS devices that have been or are still exploited in the wild.
Zyxel claims that over 1 million businesses use its networking solutions across 150 markets worldwide.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.