A Zyxel GS1900 switch exploit has compromised nearly 1,000 devices across 48 countries, prompting CISA to add CVE-2026-7273 to its Known Exploited Vulnerabilities catalogue and order Federal Civilian Executive Branch agencies to patch their switches by Thursday. The vulnerability has been attributed by threat intelligence company GreyNoise to a suspected Chinese-speaking malicious cyber actor, and the damage already done is considerably more specific than most KEV additions warrant.
The flaw itself is a stack-based buffer overflow in the CGI programme of GS1900 series switches. It allows an unprivileged attacker on the local area network to execute operating system commands by sending maliciously crafted HTTP requests. Zyxel released firmware updates to address the issue on 16 June and advised customers to upgrade for what it called ‘optimal protection.’ The company has not yet updated its own advisory to confirm active exploitation in the wild.
CISA was less equivocal. Adding CVE-2026-7273 to the KEV catalogue on Monday, the agency cited Binding Operational Directive 26-04 in mandating that FCEB agencies secure affected devices against ongoing attacks. ‘This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,’ CISA said, while also encouraging all organisations (not just federal ones) to treat KEV catalogue entries as remediation priorities.
What the Zyxel GS1900 Switch Exploit Actually Stole
GreyNoise published its own account on Monday, tracing the first signs of exploitation to the previous Thursday. According to Help Net Security, the attacks themselves occurred on or about 17 August, with the threat actor extracting device configuration data, networking information, and hashed root-level credentials from each compromised switch. GreyNoise confirmed this was ‘the first publicly documented case of exploitation in the wild’ of CVE-2026-7273 as of 17 September 2026.
The method was deliberate and somewhat sophisticated. According to SecurityWeek, the threat actor deployed a heavily obfuscated Python script to carry out the exfiltration across 996 vulnerable devices. The geographic spread of victims skews towards Italy, the US, Taiwan, South Korea, and several EU countries, according to Help Net Security.
One detail that stands out: 564 of the 996 compromised switches were running factory default credentials at the time of the attack, according to GreyNoise. That is more than half the victim pool handing over the keys with no resistance at all. It is a reminder that CVE exploitation and basic credential hygiene are not separate problems.
A Familiar Pattern for Zyxel Devices
The GS1900 series finds itself in this position partly for structural reasons. Zyxel devices are widely deployed by internet service providers as default equipment bundled into new service contracts, which means large numbers of them sit on networks with minimal post-installation configuration. That combination of broad deployment and inconsistent hardening makes them a recurring target.
CISA currently tracks 13 Zyxel vulnerabilities across the company’s routers, switches, firewalls, and NAS devices that have been, or still are, actively exploited. The CVE-2026-7273 addition brings fresh urgency to that list, particularly given the documented exfiltration of credential data that could facilitate further access to compromised networks.
The pattern also echoes an episode from February, when Zyxel disclosed that it had no plans to patch a pair of actively exploited zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers still available for purchase online. Rather than issuing fixes, the company advised customers to replace the hardware entirely. The GS1900 situation is different in that patches do exist, but the window between Zyxel’s June firmware release and confirmed exploitation underscores how slowly updates propagate across real-world deployments.
Zyxel states that over 1 million businesses use its networking solutions across 150 markets worldwide. FCEB agencies have until Thursday to demonstrate they are not among the unpatched remainder; everyone else has no formal deadline, but 996 confirmed victims and a trove of harvested credentials provide a fairly compelling argument for urgency.

