Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: zyxel (1 article)Clear

CISA flags exploited Zyxel switch flaw enabling unauthenticated command execution over the LAN

CISA added a Zyxel GS1900 series switch flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation. Tracked as CVE-2026-7273 and rated 8.8, it is a stack-based buffer overflow in the switch firmware's CGI program that lets a LAN-based, unauthenticated attacker run operating system commands through a crafted HTTP request. Zyxel patched it in June across the GS1900-8 through GS1900-48HPv2 models. GreyNoise reported that a suspected Chinese-speaking actor has weaponized the flaw since August 17, successfully exploiting and exfiltrating data from 996 Zyxel switches across 48 countries. Federal agencies must patch under the KEV directive, and other operators should treat exposed management interfaces as a priority.

Check
Inventory Zyxel GS1900 switches, confirm firmware against the fixed versions, and update immediately while removing switch management interfaces from untrusted LAN segments.
Affected
Unpatched GS1900 switches let a LAN-based unauthenticated attacker run operating system commands via crafted HTTP requests, and active campaigns are already exfiltrating data.
Fix
Apply Zyxel's June firmware fixes, segment and restrict switch management access, and hunt for signs of prior compromise on exposed devices.