Zyxel GS1900 CVE-2026-7273 Hit CISA’s KEV — Patch Those Access Switches Now
If your Midtown professional firm, Staten Island medical practice, Brooklyn warehouse, or Queens clinic still runs Zyxel GS1900 access switches for PoE phones, cameras, APs, or desk drops, treat CVE-2026-7273 as a same-week emergency — not a quiet Friday firmware change. Zyxel published a security advisory for a stack-based buffer overflow in the GS1900 CGI path on June 16, 2026. On September 21, 2026, CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. Federal civilian agencies face a remediation due date of September 24, 2026. Private NYC shops are not under Binding Operational Directive the same way, but a LAN-reachable, unauthenticated switch bug with a three-day federal clock should jump the queue ahead of “nice to have” lifecycle work.
Secondary reporting (The Hacker News, September 22, 2026) restates a CVSS score of 8.8 for CVE-2026-7273 and summarizes GreyNoise research on active abuse against GS1900 devices. This post is a practical checklist for NYC SMBs and the MSPs who support them. Named sources only: Zyxel’s advisory, CISA’s September 21 KEV alert and catalog entry, NVD’s CVE summary, and The Hacker News’ September 22 write-up citing GreyNoise. No invented percentages. No exploit recipes.
What CVE-2026-7273 actually is
Per Zyxel’s security advisory (initial release 2026-06-16), a stack-based buffer overflow in the CGI program of Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. NVD’s CVE-2026-7273 summary aligns with that language and points back to the same Zyxel advisory as the vendor reference.
That combination matters for operators: you do not need a stolen admin password for the attack path Zyxel describes. You need LAN reach to the switch’s HTTP management surface on a vulnerable firmware build. In many NYC small offices, that “LAN” is the same flat VLAN that carries guest Wi-Fi spillover, contractor laptops, IoT cameras, and the receptionist PC — not a locked-down OOB management VRF.
Important scope notes from Zyxel:
- Affected: listed GS1900 models on the firmware trains shown in Zyxel’s table (through the “.1)C0” builds and earlier for each SKU).
- Not affected (per Zyxel): on-market products not listed in the advisory table remain unaffected.
- Fix: install the corresponding “.2)C0” patched firmware for each model.
If you do not run GS1900 switches, this CVE is not your patch target. If you run any of the listed SKUs — including a quiet closet switch someone bought years ago for PoE phones — keep reading.
Why CISA put it on the KEV — and why September 24 matters
CISA’s September 21 news alert states it added one vulnerability to the KEV catalog based on evidence of active exploitation: CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability. The public KEV catalog entry lists:
- Vendor / product: Zyxel / GS1900 Series Switches
- Date added: 2026-09-21
- Due date: 2026-09-24
- Related CWE: CWE-121 (stack-based buffer overflow)
- Forensic triage required per BOD 26-04: Yes
- Known ransomware campaign use: Unknown
Required action language points agencies at Zyxel’s vendor instructions and BOD 26-04 guidance (including forensics triage expectations for exposed assets that grant total control after exploitation). For a five-person accounting firm on South Avenue or a multi-site practice in Queens, the practical takeaway is simple: when Zyxel and CISA both say a LAN-reachable CGI overflow can lead to OS command execution on the switch that wires your floor, you do not wait for the next “quiet” maintenance window if any GS1900 is still on an affected build.
Fixed firmware — what to upgrade to
Zyxel’s Fixed Software table in the June 16, 2026 advisory is the authoritative map. Affected versions are the “.1)C0 and earlier” trains; patched releases are the matching “.2)C0” builds:
- GS1900-8 — 2.90(AAHH.1)C0 and earlier → 2.90(AAHH.2)C0
- GS1900-8HP — 2.90(AAHI.1)C0 and earlier → 2.90(AAHI.2)C0
- GS1900-10HP — 2.90(AAZI.1)C0 and earlier → 2.90(AAZI.2)C0
- GS1900-16 — 2.90(AAHJ.1)C0 and earlier → 2.90(AAHJ.2)C0
- GS1900-24 — 2.90(AAHL.1)C0 and earlier → 2.90(AAHL.2)C0
- GS1900-24E — 2.90(AAHK.1)C0 and earlier → 2.90(AAHK.2)C0
- GS1900-24EP — 2.90(ABTO.1)C0 and earlier → 2.90(ABTO.2)C0
- GS1900-24HPv2 — 2.90(ABTP.1)C0 and earlier → 2.90(ABTP.2)C0
- GS1900-48 — 2.90(AAHN.1)C0 and earlier → 2.90(AAHN.2)C0
- GS1900-48HPv2 — 2.90(ABTQ.1)C0 and earlier → 2.90(ABTQ.2)C0
Download firmware only from Zyxel’s official download library for the exact model. Follow the release notes for that build before you flash. Do not grab “a GS1900 image” from a random mirror — wrong SKU firmware is how you turn a KEV patch into an unplanned outage.
Active exploitation context (what public reporting says)
CISA’s September 21 alert is explicit that the addition is based on evidence of active exploitation. The Hacker News’ September 22 article summarizes GreyNoise findings that a suspected Chinese-speaking actor has weaponized the flaw since August 17, 2026, with reported compromise and data exfiltration from hundreds of GS1900 switches across dozens of countries, including the U.S. Per that reporting, the abuse chain involved retrieving a collector script (via TFTP in the reported pattern) and collecting configuration and credential-related material from affected devices. That is threat reporting, not a how-to — and it is exactly why “the management GUI is only on the LAN” is not a comfort blanket for flat SMB networks.
Zyxel’s public advisory revision history, as of the sources cited here, still lists the June 16, 2026 initial release and does not itself restate the later KEV / active-exploitation framing. Operators should treat CISA’s KEV entry and contemporaneous threat reporting as the urgency signal, and Zyxel’s firmware table as the fix map.
What to do this morning (MSP / NYC SMB checklist)
1. Inventory every GS1900
List model, serial, management IP, firmware string, PoE role (phones, APs, cameras), and whether HTTP/HTTPS management is reachable from user VLANs, guest SSIDs, or contractor segments. Include quiet closet switches, secondary sites in Brooklyn or Queens, and “temporary” PoE boxes that became permanent. Confirm you are not confusing GS1900 access switches with unrelated Zyxel firewall or CPE products that had their own historical KEV entries — different CVEs, different patch trains.
2. Patch — land on the matching .2)C0 build
Schedule an emergency change for every affected SKU. Target the exact patched release from Zyxel’s table for that model. Plan a brief outage window: access-switch reboots drop phones, cameras, and Wi-Fi APs on that stack. For Midtown and outer-borough sites that still live on PoE desk phones during business hours, document the reboot order and a rollback image before you start.
3. Shrink who can talk to the CGI surface
Zyxel’s own description is LAN-based and unauthenticated against the CGI program. Until every box is on .2)C0, move switch management to a dedicated management VLAN or jump-host path, and block user/guest VLANs from reaching TCP 80/443 on switch IPs. That is exposure reduction, not a substitute for the firmware fix.
4. Hunt for odd management and TFTP behavior
Review switch logs and upstream firewall/flow logs for unexpected management sessions to GS1900 IPs, unusual firmware or file-transfer activity, and outbound connections from switch management addresses that do not match your change calendar. If GreyNoise-style reporting is in your threat feed, use their published detection guidance — do not invent IoCs. Preserve configs and support bundles before you factory-reset anything that looks compromised.
5. If compromise is suspected — rebuild trust, do not “clean in place”
Treat a switch that may have executed attacker commands as untrusted infrastructure. Re-image or factory-reset to known-good firmware, restore from a known-good config taken before the suspicious window when possible, and rotate any credentials, SNMP communities, RADIUS secrets, and admin passwords that lived on or were pushed through that box. Re-validate VLAN, ACL, and PoE settings after rebuild — a switch that “mostly forwards frames” after a root-capable incident is not a success criterion.
6. Harden the boring controls after the patch
Disable unused HTTP management if you can run HTTPS-only (or serial/SSH-only) admin. Keep management off the open internet. Separate user, guest, and IoT VLANs from the management plane. Ship switch syslogs to an external collector so a compromised box cannot erase your only trail. None of that replaces the .2)C0 patch — it reduces how ugly the next LAN-management incident gets.
How MicroSky thinks about this for managed clients
Access switches are easy to ignore until they are the lateral-movement stepping stone. Staten Island offices, Queens clinics, and Manhattan professional firms often treat GS1900-class PoE switches as “set and forget” closet gear — until a LAN-reachable CGI overflow turns the floor switch into an OS command-execution target. We treat KEV-listed switching the same way we treat firewall, email-gateway, and identity KEVs covered elsewhere on this blog: inventory first, emergency patch second, exposure shrink and log review third, rebuild and credential rotation if anything looks off.
For clients we manage, the work looks like confirming every GS1900 model and firmware string (including quiet secondary closets), pushing the correct .2)C0 image per SKU, restricting who can reach HTTP management, reviewing management and flow logs around the August–September exploitation window described in public reporting, and escalating anything that smells like persistence to a formal incident path. For clients who self-manage on-prem switching, the same checklist applies — and if user VLANs can still hit switch management IPs, close that path the same day you schedule the firmware change.
Bottom line
CVE-2026-7273 is an actively exploited stack-based buffer overflow in Zyxel GS1900 CGI firmware. CISA added it to the KEV catalog on September 21, 2026, with a September 24 federal remediation due date. Patch every listed model to the matching 2.90(.2)C0 release from Zyxel, shrink LAN reach to the management plane until you are done, hunt for odd management activity, and rebuild if compromise is suspected. If you need a local MSP to run that checklist across Midtown, Staten Island, Brooklyn, or Queens sites, call MicroSky at (718) 672-2177 or visit https://microskyms.com.

