SMB / branch switches just got a federal clock. On Monday CISA put CVE-2026-7273 on the Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to remediate by Thursday under BOD 26-04. BleepingComputer (Sep 22) and SecurityWeek (Sep 22) carried the order; Zyxel’s June 16 advisory is still the primary patch source.
The flaw is a stack-based buffer overflow in the CGI program on Zyxel GS1900 series firmware. Per Zyxel / NVD: a LAN-based, unauthenticated attacker can potentially execute OS commands via a crafted HTTP request. SecurityWeek cites CVSS 8.8. Ten in-support models are listed (GS1900-8 through GS1900-48HPv2); fix line is model-specific 2.90(….2)C0 builds. Zyxel: on-market products not in that table remain unaffected.
GreyNoise (Kapibala campaign write-up; first public ITW claim as of Sep 17) ties exploitation to a suspected Chinese-speaking malicious cyber actor using a PyArmor-obfuscated Python exploit. GreyNoise: sensitive data exfiltrated from 996 GS1900 switches across 48 countries — hashed root credentials, configuration, networking details. SecurityWeek adds: 564 of those devices still had factory-default credentials. Script targets firmware 2.10–2.90 on GS1900-24 with CLI options for other in-scope builds. CISA has not published its own victim census; treat agency-side impact as Undisclosed.
POV: patch has been free since mid-June. KEV + Thursday BOD is the escalation, not the discovery. Upgrade every listed GS1900 to the matching 2.90(….2)C0, kill factory defaults, and keep management off hostile LANs. Sources: Zyxel advisory 06-16-2026, NVD CVE-2026-7273, GreyNoise Kapibala post, CISA KEV / BOD 26-04 via BleepingComputer + SecurityWeek Sep 22.
