On September 22, 2026, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog. Zyxel patched the issue in June, but KEV inclusion materially changes its operational priority because there is now evidence of exploitation in the wild.

What CVE-2026-7273 allows

Zyxel describes a stack-based buffer overflow in the CGI program used by GS1900 switch firmware. A LAN-based, unauthenticated attacker can send a crafted HTTP request and potentially execute operating-system commands.

The LAN requirement matters. The vendor advisory does not justify describing the issue as an Internet-wide pre-auth RCE. An attacker needs network access to the vulnerable management surface. In an environment where an attacker has already gained a foothold, however, a managed switch can be a valuable target for lateral movement and infrastructure control.

Why CISA KEV inclusion matters

KEV is not simply a list of high-scoring CVEs. CISA uses it for vulnerabilities with evidence of real-world exploitation. For CVE-2026-7273, that makes remediation more urgent than a decision based on CVSS alone.

The primary sources reviewed for this analysis do not currently provide enough public indicators of compromise to build a reliable IoC checklist. We therefore do not manufacture one.

Affected models and fixed firmware

Zyxel lists these patched releases:

Model Affected version Fixed firmware
GS1900-8 2.90(AAHH.1)C0 and earlier 2.90(AAHH.2)C0
GS1900-8HP 2.90(AAHI.1)C0 and earlier 2.90(AAHI.2)C0
GS1900-10HP 2.90(AAZI.1)C0 and earlier 2.90(AAZI.2)C0
GS1900-16 2.90(AAHJ.1)C0 and earlier 2.90(AAHJ.2)C0
GS1900-24 2.90(AAHL.1)C0 and earlier 2.90(AAHL.2)C0
GS1900-24E 2.90(AAHK.1)C0 and earlier 2.90(AAHK.2)C0
GS1900-24EP 2.90(ABTO.1)C0 and earlier 2.90(ABTO.2)C0
GS1900-24HPv2 2.90(ABTP.1)C0 and earlier 2.90(ABTP.2)C0
GS1900-48 2.90(AAHN.1)C0 and earlier 2.90(AAHN.2)C0
GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier 2.90(ABTQ.2)C0

Zyxel states that on-market products not listed in its advisory are unaffected. For hardware outside the vulnerability-support period, administrators should verify the model's support status and plan replacement when no supported fixed release exists.

What to check now

  1. Inventory GS1900 switches and record the exact model and installed firmware.
  2. Compare each release against Zyxel's official matrix rather than relying on the family name alone.
  3. Install the fixed firmware for the specific model.
  4. Restrict management access to the administrative networks and hosts that actually need it.
  5. If a vulnerable device was reachable from untrusted segments, reassess available logs and configuration. A lack of public IoCs should not be interpreted as proof that exploitation did not occur.

Sources

  • CISA, Known Exploited Vulnerabilities Catalog, CVE-2026-7273 added September 22, 2026.
  • Zyxel, Security advisory for stack-based buffer overflow vulnerability in GS1900 series switches, June 16, 2026.