THE US Cybersecurity and Infrastructure Security Agency (CISA) has added a Zyxel GS1900 Series switch vulnerability, tracked as CVE-2026-7273 and rated 8.8 by CVSS, to its Known Exploited Vulnerabilities catalogue. The flaw is a stack-based buffer overflow in the switches’ CGI component. According to Zyxel, an unauthenticated attacker on the local network could send a specially crafted HTTP request and potentially execute operating-system commands on the device.
The affected models include the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48 and GS1900-48HPv2. Zyxel has issued fixes in firmware versions 2.90(AAHH.2)C0, 2.90(AAHI.2)C0, 2.90(AAZI.2)C0, 2.90(AAHJ.2)C0, 2.90(AAHL.2)C0, 2.90(AAHK.2)C0, 2.90(ABTO.2)C0, 2.90(ABTP.2)C0, 2.90(AAHN.2)C0 and 2.90(ABTQ.2)C0 respectively; earlier listed versions are affected.
CISA did not provide details of the exploitation or identify those responsible, and Zyxel had not confirmed active exploitation in its advisory. Under CISA’s directive, US federal agencies must address the vulnerability by 24 September 2026.