CISA Gives Agencies 3 Days on Zyxel's June-Patched Flaw
Security / news
CISA Gives Agencies 3 Days on Zyxel's June-Patched Flaw
The switch bug needs an attacker already on the local network, the kind of precondition CISA's own directive says should mean a longer runway, not a shorter one.

CISA added a stack-based buffer overflow in Zyxel's GS1900 switches to its Known Exploited Vulnerabilities catalog on Sept. 21, citing active exploitation of a flaw the vendor had already patched more than three months earlier.
The vulnerability, tracked as CVE-2026-7273, carries a CVSS 3.1 score of 8.8 and lets an unauthenticated attacker who already has access to the same local network run operating-system commands on the switch through a crafted HTTP request, according to the National Vulnerability Database. Zyxel's own advisory, published June 16, traces the bug to the CGI program in the switch's web management interface and says nothing about exploitation at the time.
Ten switch models, one shared flaw
The advisory covers 10 models in the GS1900 line, from the compact eight-port GS1900-8 up to the 48-port GS1900-48HPv2, all running firmware built on the same CGI code. Zyxel shipped a fixed build for every model June 16, each identified by its own version string rather than a single shared number.
| Affected model | Patched firmware |
|---|---|
| GS1900-8 | 2.90(AAHH.2)C0 |
| GS1900-8HP | 2.90(AAHI.2)C0 |
| GS1900-16 | 2.90(AAHJ.2)C0 |
| GS1900-24 | 2.90(AAHL.2)C0 |
| GS1900-48 | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | 2.90(ABTQ.2)C0 |
A deadline that cuts against CISA's own rule
CISA's binding operational directive on the catalog, BOD 26-04, says it "requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by CVEs listed in CISA's KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities." CVE-2026-7273 does not fit that description on its own terms: the flaw's own CVSS vector, AV:A, means it can only be reached from an adjacent network, not from the open internet, and a properly configured GS1900 switch has no reason to expose its CGI management interface to a public IP address.
CISA's own catalog entry nonetheless set a due date of Sept. 24, three days after the addition, the same short window the directive reserves for internet-facing flaws that grant full control with no access barrier at all. The alert announcing the addition does not explain the gap between the deferral principle in its own directive and the deadline it assigned this particular flaw.
No public account of how it is being exploited
Neither CISA's alert nor Zyxel's advisory says who is behind the exploitation or how attackers are finding switches to target. That is normal for a KEV catalog entry, which typically states only that exploitation occurred, not how, but it leaves a genuine gap: a flaw requiring LAN adjacency is usually found either through an already-compromised device pivoting sideways, or through a switch whose management interface was mistakenly bridged onto the internet, and nothing published so far says which. It is a quieter kind of vulnerability than WordPress's Click2Shell chain, which earned a detailed technical write-up but no CVE number at all; CVE-2026-7273 has the opposite problem, a formal identifier and a federal deadline attached to almost no public detail about the attack itself.
What GS1900 operators should do
Zyxel's fix is not automatic. Administrators need to open each switch's web dashboard, check the firmware version against the table above, and manually apply the update, the same manual step that left Mathspace exposed for 23 days after Metabase had already shipped a fix for an unrelated flaw. Operators who cannot patch immediately should confirm the switch's CGI interface is not reachable from outside its local subnet, which closes the only path CVE-2026-7273 needs.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.