Zyxel GS1900 Flaw CVE-2026-7273 Hits CISA KEV After 996 Switches Compromised Across 48 Countries

Zyxel GS1900 Flaw CVE-2026-7273 Hits CISA KEV After 996 Switches Compromised Across 48 Countries

Zyxel GS1900 Flaw CVE-2026-7273 Hits CISA KEV After 996 Switches Compromised Across 48 Countries

CISA has ordered federal agencies to patch an actively exploited vulnerability in Zyxel GS1900 series switches by September 24, after adding the flaw to its Known Exploited Vulnerabilities catalog on Monday. The vulnerability, tracked as CVE-2026-7273 (CVSS 8.8), is a stack-based buffer overflow in the CGI program of the switch firmware that lets a LAN-based, unauthenticated attacker execute operating system commands via a crafted HTTP request. Zyxel shipped fixes back on June 16 — but threat intelligence suggests the window since then has been very busy.

GreyNoise reported on Monday that it spotted the first signs of exploitation last Thursday. A suspected Chinese-speaking malicious cyber actor, it said, has exploited and exfiltrated sensitive data from 996 Zyxel GS1900 switches across 48 countries — the first publicly documented case of CVE-2026-7273 being exploited in the wild as of September 17. The campaign targeted more than a dozen other vulnerabilities affecting a wide range of software and technology products. Zyxel has yet to update its advisory to confirm the active exploitation.

What's Affected and What to Install

Ten GS1900 models are affected — the GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, -48, and -48HPv2 — on firmware 2.90(AAxx.1)C0 and earlier, each with a matching patched build in the 2.90(AAxx.2)C0 line. The flaw was discovered and reported by Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo of ISCAS. CISA's Binding Operational Directive 26-04 gives Federal Civilian Executive Branch agencies until September 24, and the agency encourages every organization to prioritize KEV remediation, calling this class of bug "a frequent attack vector for malicious cyber actors" that "poses significant risks to the federal enterprise."

The scale is worth pausing on: Zyxel says more than one million businesses across 150 markets use its networking solutions, and its devices are often provided as default, out-of-the-box equipment by internet service providers — which puts unmanaged, unpatched switches inside networks whose owners may not know the hardware exists. CISA already tracks 13 Zyxel vulnerabilities in the KEV catalog, spanning the company's routers, switches, firewalls, and NAS devices. In February, Zyxel said it would not patch two actively exploited zero-day flaws in end-of-life routers still available for sale, and instead "strongly" advised customers to replace them.

The same week, Arctic Wolf warned of active exploitation of CVE-2026-32996 (CVSS 7.3), a local privilege escalation in Veeam Agent for Microsoft Windows. The Veeam Endpoint Backup service caches an elevated administrator principal against a client-controlled session UID that is not bound to the requesting user or connection — and those UIDs are written to a log file any standard user can read. With a valid UID, an attacker with local access runs commands as SYSTEM; a public proof-of-concept demonstrates it by running whoami and writing the output to a file.

What Should You Do?

  1. Upgrade GS1900 firmware now to the 2.90(AAxx.2)C0 build for your model — the federal deadline is September 24, and exploitation is already at scale.
  2. Inventory ISP-provided gear. If a switch came with the internet connection, it is probably unmapped, unpatched, and LAN-exposed.
  3. Segment switch management interfaces. The flaw is reachable by any unauthenticated host on the LAN, so management VLANs and ACLs shrink the blast radius to nearly zero.
  4. Check running configs and admin sessions on any GS1900 exposed since June, and treat unexpected changes as compromise indicators.
  5. For Veeam: check the vendor's guidance for CVE-2026-32996, and restrict interactive local access to backup hosts in the meantime.

The WAF Angle

This is a web exploit in miniature: the entry point is a crafted HTTP request to a CGI program — the exact attack shape a WAF exists to catch — except the web app lives on a switch nobody fronts with a WAF. Three lessons. First, every management plane is a web application: inventory the HTTP and CGI interfaces on your network gear, because attackers already have. Second, "LAN" is not a trust boundary: an unauthenticated, LAN-reachable command-execution flaw means one compromised laptop, a bridged guest Wi-Fi, or a malicious insider equals full device control — segment management networks accordingly. Third, virtual patching still applies when you cannot patch firmware today: ACLs and IPS signatures in front of the management plane buy you the maintenance window, and KEV entries with mass exploitation and a three-day federal deadline should jump to the top of your entire remediation queue.

Sources