Threat Landscape

CISA KEV: Zyxel GS1900 CVE-2026-7273. Feds have until Thursday.

CVE-2026-7273 (CVSS 8.8): LAN-based unauth stack overflow in GS1900 CGI → OS command execution. CISA added it to KEV Monday and set a Thursday BOD 26-04 deadline. GreyNoise: first public ITW as of Sep 17 — 996 switches across 48 countries, hashed root credentials + config exfiltrated. Patches out since June 16.

Sep 22, 2026 · 3 min read

SMB / branch switches just got a federal clock. On Monday CISA put CVE-2026-7273 on the Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to remediate by Thursday under BOD 26-04. BleepingComputer (Sep 22) and SecurityWeek (Sep 22) carried the order; Zyxel’s June 16 advisory is still the primary patch source.

The flaw is a stack-based buffer overflow in the CGI program on Zyxel GS1900 series firmware. Per Zyxel / NVD: a LAN-based, unauthenticated attacker can potentially execute OS commands via a crafted HTTP request. SecurityWeek cites CVSS 8.8. Ten in-support models are listed (GS1900-8 through GS1900-48HPv2); fix line is model-specific 2.90(….2)C0 builds. Zyxel: on-market products not in that table remain unaffected.

GreyNoise (Kapibala campaign write-up; first public ITW claim as of Sep 17) ties exploitation to a suspected Chinese-speaking malicious cyber actor using a PyArmor-obfuscated Python exploit. GreyNoise: sensitive data exfiltrated from 996 GS1900 switches across 48 countries — hashed root credentials, configuration, networking details. SecurityWeek adds: 564 of those devices still had factory-default credentials. Script targets firmware 2.10–2.90 on GS1900-24 with CLI options for other in-scope builds. CISA has not published its own victim census; treat agency-side impact as Undisclosed.

POV: patch has been free since mid-June. KEV + Thursday BOD is the escalation, not the discovery. Upgrade every listed GS1900 to the matching 2.90(….2)C0, kill factory defaults, and keep management off hostile LANs. Sources: Zyxel advisory 06-16-2026, NVD CVE-2026-7273, GreyNoise Kapibala post, CISA KEV / BOD 26-04 via BleepingComputer + SecurityWeek Sep 22.

Sources