CISA adds actively exploited Zyxel GS1900 switch flaw CVE-2026-7273 to KEV; 996 devices compromised across 48 countries
CISA added Zyxel GS1900 stack-based buffer overflow CVE-2026-7273 (CVSS 8.8) to its KEV catalog on September 21, 2026 with a September 24 federal remediation deadline; GreyNoise says a suspected Chinese-speaking actor assessed as Red Heron or closely related…
On September 21, 2026, CISA added CVE-2026-7273 — a stack-based buffer overflow (CWE-121) in the CGI program of Zyxel GS1900 series switches — to its Known Exploited Vulnerabilities catalog, and the Canadian Centre for Cyber Security issued Update 1 to advisory AV26-603, originally published June 16, 2026. Scored 8.8 under CVSS v3.1, the flaw lets an unauthenticated attacker on the local or adjacent network execute operating-system commands via a crafted HTTP request to the switch's management interface; successful compromise can enable traffic interception, credential theft, and lateral movement. Affected models span GS1900-8 through GS1900-48HPv2, with the GS1900-48HPv2 affected through firmware 2.90(ABTQ.1)C0; Zyxel shipped fixes on June 16 in second-release 2.90 firmware builds across ten GS1900 models. Under BOD 26-04, FCEB agencies must apply mitigations, perform forensic triage of exposed assets, or stop using affected products by September 24, 2026 (Security Affairs instead cites BOD 22-01). GreyNoise attributes the exploitation to a suspected Chinese-speaking actor assessed as Red Heron or closely related: an obfuscated Python script pulled hashed root credentials, configuration, and network data from 996 devices across 48 countries, 564 of which still used factory-default credentials, while the actor targeted over a dozen other vulnerabilities, chained Ubiquiti bugs for remote code execution, attacked WordPress sites in July, and stole more than 18,000 records from a Western government body. BleepingComputer dates GreyNoise's first documented in-the-wild exploitation to September 17, 2026 and describes the flaw as a novel vector since mid-September, while SecurityWeek and Help Net Security place the campaign in August, and Help Net Security's claim that the exploit was contained in June 2026 conflicts with both. CISA named no attackers, has not linked the flaw to ransomware campaigns, and tracks 13 total exploited Zyxel vulnerabilities across routers, switches, firewalls, and NAS devices; ISCAS researchers are credited with reporting the flaw. The Hacker News reported that CISA had not confirmed active exploitation, contrary to the other seven reports, and BleepingComputer cites CVE-2024-40891 and Help Net Security cites CVE-2026-32996 with no further detail.
- CVE-2026-7273 is a critical stack-based buffer overflow (CWE-121) in the CGI program of Zyxel GS1900 series switches, scored CVSS v3.1 8.8.
Coverage timelineoldest first · each row is one article
- · 5d agoZyxel security advisory (AV26-603) – Update 1
Canadian Centre for Cyber Security· 71
Canada's Cyber Centre says Zyxel GS1900 buffer overflow CVE-2026-7273 is now in CISA's KEV catalog.
- · 5d agoZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The Hacker News· 90
Zyxel disclosed an active exploitation of a stack-based buffer overflow in its GS1900 switch firmware (CVE-2026-7273), enabling OS command execution.
- · 5d agoCISA Warns of Zyxel GS1900 Switches Flaw Actively Exploited in Attacks
Cyber Security News· 80
Vulnerabilities in this storyAll →
- CVE-2024-408918.822%Post-Authentication OS Command Injection in Zyxel DSL CPE Devicespublished · Zyxel DSL CPE Devices (multiple models) KEV