The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that attackers are actively exploiting a high-severity vulnerability affecting Zyxel GS1900 series switches. The flaw, designated CVE-2026-7273, arises from a stack-based buffer overflow in the CGI program, permitting unauthenticated attackers on the local area network to execute arbitrary operating system commands through specially crafted HTTP requests.

Zyxel released patches for the vulnerability on June 16, urging customers to update their firmware immediately. However, CISA did not wait for widespread adoption: the agency added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog on Monday and issued Binding Operational Directive (BOD) 26-04, requiring all Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by Thursday.

According to CISA, "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise." The agency also stated, "While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities."

Threat intelligence firm GreyNoise documented the first exploitation attempts last Thursday, revealing that a suspected Chinese-speaking threat actor has compromised approximately 1,000 Zyxel GS1900 switches globally. GreyNoise reported that "The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries" as part of a broader campaign targeting multiple vulnerabilities across various products.

Zyxel equipment remains a frequent target because numerous internet service providers distribute these devices as standard equipment with new service contracts. The company's widespread deployment—over 1 million businesses rely on Zyxel networking solutions across 150 markets—makes such vulnerabilities particularly consequential.

This incident reflects a troubling pattern with Zyxel. In February, the company announced it would not patch two actively exploited zero-day vulnerabilities (CVE-2024-40891 and CVE-2024-40891) in end-of-life routers, instead recommending customers replace affected devices entirely. CISA currently tracks 13 Zyxel vulnerabilities spanning routers, switches, firewalls, and NAS devices that have been exploited or remain under active attack.