The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal civilian executive agencies to secure Zyxel GS1900 switches affected by CVE-2026-7273 before Thursday, after observing its active exploitation in attacks targeting data theft. The agency added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on Monday, making remediation mandatory for entities covered by Binding Operational Directive BOD 26-04.
Vulnerability Allows Remote Command Execution
CVE-2026-7273 results from a stack overflow in CGI software within the switches. An attacker without privileges on the local network can execute system commands by sending specially crafted HTTP requests. Zyxel released security updates to address the issue on June 16, urging customers to upgrade the firmware for optimal protection.
Zyxel has not yet updated its advisory to confirm active exploitation, but GreyNoise said in a report released Monday that it observed the first signs of exploitation on September 17, 2026. The company said a suspected Chinese-speaking threat actor exploited the vulnerability as part of a broader campaign and managed to compromise and extract sensitive data from 996 Zyxel switches in 48 countries.
Affected Models and Versions
- GS1900-8: Version 2.90(AAHH.1)C0 and earlier; fix 2.90(AAHH.2)C0.
- GS1900-8HP: Version 2.90(AAHI.1)C0 and earlier; fix 2.90(AAHI.2)C0.
- GS1900-10HP: Version 2.90(AAZI.1)C0 and earlier; fix 2.90(AAZI.2)C0.
- GS1900-16: Version 2.90(AAHJ.1)C0 and earlier; fix 2.90(AAHJ.2)C0.
- GS1900-24, GS1900-24E, and GS1900-24EP: Versions 2.90(AAHL.1)C0, 2.90(AAHK.1)C0, and 2.90(ABTO.1)C0 and earlier, with corresponding fixes 2.90(AAHL.2)C0, 2.90(AAHK.2)C0, and 2.90(ABTO.2)C0.
- GS1900-24HPv2: Version 2.90(ABTP.1)C0 and earlier; fix 2.90(ABTP.2)C0.
- GS1900-48: Version 2.90(AAHN.1)C0 and earlier; fix 2.90(AAHN.2)C0.
- GS1900-48HPv2: Version 2.90(ABTQ.1)C0 and earlier; fix 2.90(ABTQ.2)C0.
Why Does This Matter?
The shift from having an available update to listing the vulnerability in the KEV catalog means that organizations are required to treat it as a confirmed risk, not a theoretical possibility. The mandatory deadline applies directly to U.S. federal civilian executive agencies, but CISA urged all organizations to prioritize KEV vulnerabilities as part of exposure-based risk management.
The warning is especially significant because Zyxel switches may be part of network infrastructure provided by internet service providers as virtual devices, expanding the scope of potentially exposed equipment. CISA has not disclosed details of the attacks, while GreyNoise data points to a global campaign and data extraction from multiple devices; therefore, the nature of the stolen data, the responsible party, and the ultimate target remain open questions.
CISA is currently tracking 13 vulnerabilities in Zyxel devices, including routers, switches, firewalls, and NAS devices, that have previously been exploited or continue to be exploited. Zyxel says more than one million companies use its solutions in 150 markets worldwide.