The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal civilian agencies to patch a high-severity flaw in Zyxel GS1900 series switches after confirming active exploitation. The vulnerability, tracked as CVE-2026-7273, is a stack-based buffer overflow in the device’s CGI program that allows unauthenticated attackers on the local network to execute OS commands via specially crafted HTTP requests.

CISA added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog on Monday and, under Binding Operational Directive (BOD) 26-04, gave Federal Civilian Executive Branch (FCEB) agencies until Thursday to secure affected switches. “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA said, urging all organizations, not just federal agencies, to prioritize remediation.

Zyxel released firmware updates addressing the issue on June 16 and recommended customers upgrade for “optimal protection,” but the vendor has not updated its advisory to acknowledge active exploitation.

Affected Models

  • GS1900-8, GS1900-8HP, GS1900-10HP
  • GS1900-16, GS1900-24, GS1900-24E
  • GS1900-24EP, GS1900-24HPv2
  • GS1900-48, GS1900-48HPv2

Each model has a corresponding patched firmware version available from Zyxel; administrators should confirm they are running the updated builds rather than the vulnerable earlier releases.

Exploitation Details

Threat intelligence firm GreyNoise reported spotting the first signs of exploitation last Thursday, attributing the activity to a suspected Chinese-speaking malicious cyber actor. According to GreyNoise, the group used a novel exploit for CVE-2026-7273 as part of a broader campaign targeting more than a dozen other vulnerabilities across various software and hardware products. The company said the attacker successfully compromised and exfiltrated sensitive data from 996 Zyxel GS1900 switches across 48 countries, marking the first publicly documented case of in-the-wild exploitation of this flaw.

Zyxel devices are frequently targeted because many internet service providers ship them as default equipment for new internet contracts, giving attackers a large and often unmanaged attack surface. CISA currently tracks 13 Zyxel vulnerabilities across the company’s routers, switches, firewalls, and NAS devices that have been or are being exploited. Zyxel says its networking products are used by over 1 million businesses across 150 markets.