Zyxel GS1900 CVE-2026-7273 Is Actively Exploited: Patch These 10 Switch Models


CISA has added CVE-2026-7273, a Zyxel GS1900 series switch vulnerability, to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. The flaw can let an unauthenticated attacker already on the local network execute operating-system commands through a crafted HTTP request to the switch's management interface.

Zyxel rates CVE-2026-7273 at CVSS 8.8 and published patches in June 2026. CISA's KEV action makes the older vulnerability newly urgent: U.S. Federal Civilian Executive Branch agencies must remediate it by September 24, 2026. Operators of affected GS1900 switches should use the same deadline as a practical prompt to verify firmware and management-plane exposure.

The affected supported models are GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48 and GS1900-48HPv2. Zyxel says currently marketed products outside its advisory table are unaffected.

Affected models and fixed firmware

Zyxel's advisory lists the following version boundaries. The patch suffix differs by hardware model, so administrators should match the exact model before upgrading.

Model Affected firmware Fixed firmware
GS1900-8 2.90(AAHH.1)C0 and earlier 2.90(AAHH.2)C0
GS1900-8HP 2.90(AAHI.1)C0 and earlier 2.90(AAHI.2)C0
GS1900-10HP 2.90(AAZI.1)C0 and earlier 2.90(AAZI.2)C0
GS1900-16 2.90(AAHJ.1)C0 and earlier 2.90(AAHJ.2)C0
GS1900-24 2.90(AAHL.1)C0 and earlier 2.90(AAHL.2)C0
GS1900-24E 2.90(AAHK.1)C0 and earlier 2.90(AAHK.2)C0
GS1900-24EP 2.90(ABTO.1)C0 and earlier 2.90(ABTO.2)C0
GS1900-24HPv2 2.90(ABTP.1)C0 and earlier 2.90(ABTP.2)C0
GS1900-48 2.90(AAHN.1)C0 and earlier 2.90(AAHN.2)C0
GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier 2.90(ABTQ.2)C0

Zyxel says these are the models still within their vulnerability-support period that required patches. Administrators with older or end-of-support GS1900 hardware should check the exact model against Zyxel's lifecycle and firmware resources and plan replacement where a supported fixed release is unavailable.

How CVE-2026-7273 can be exploited

The vulnerability is a stack-based buffer overflow in the firmware CGI program. Zyxel says a LAN-based, unauthenticated attacker can trigger the flaw with a specially crafted HTTP request and potentially execute OS commands.

The LAN requirement materially shapes the attack surface. Exploitation requires network reachability to the vulnerable management service; it is therefore relevant to compromised endpoints, malicious insiders, poorly segmented guest or IoT networks, and any environment where the switch management interface has been exposed beyond a dedicated administration network.

CISA's KEV entry establishes that exploitation has occurred in the wild. Public advisories currently provide limited detail about the observed campaigns, so incident-response decisions should be based on the confirmed exploitation status, affected firmware and local management-plane exposure.

What administrators should do now

Patch the exact switch model first. Inventory GS1900 devices and record both the hardware model and installed firmware. Apply the fixed release from Zyxel's advisory or a later supported firmware for that model, following the vendor's upgrade procedure and configuration-backup guidance.

Restrict the management plane. Permit web administration only from dedicated management VLANs or trusted administrator hosts. Remove management access from guest, user, IoT and other untrusted segments. Internet-facing switch administration should be eliminated.

Review exposure before and after the upgrade. Check firewall and ACL policy, management VLAN membership, remote-management settings and any routes that allow ordinary client networks to reach the switch GUI. A patched device still benefits from management-plane isolation because it reduces exposure to future vulnerabilities.

Investigate potentially exposed devices. For switches that were running affected firmware and had broad management reachability, review available device, firewall and network telemetry for unexpected management requests, configuration changes, administrator activity and unusual outbound connections. Preserve relevant logs before routine retention removes them.

Why the KEV addition changes priority

Zyxel disclosed and patched CVE-2026-7273 on June 16, 2026. The September KEV addition changes the risk calculation because CISA now records evidence of real-world exploitation, moving the issue from a patch-management backlog item to an actively exploited infrastructure vulnerability.

Managed switches occupy a privileged network position and are often upgraded less frequently than servers or endpoints. A successful command-execution path on a switch can provide an attacker with a durable foothold in a part of the environment that conventional endpoint security tooling may monitor poorly.

For organizations running the affected models, the immediate decision is straightforward: identify the exact GS1900 hardware and firmware, deploy the corresponding fixed build, constrain management access, and investigate devices whose administration interface was reachable from untrusted or previously compromised systems.

Sources