CISA Gave Zyxel Switch Owners Until Thursday to Fix an Exploited LAN Flaw
CISA has given covered US federal agencies until 24 September to address an exploited flaw in Zyxel GS1900 switches. The two-day clock is unusually short, but the most important detail is easy to miss: the vulnerable management path is described as reachable from the local network.
CVE-2026-7273 is a stack-based buffer overflow in the switches’ CGI program. CISA says a LAN-based, unauthenticated attacker can send a crafted HTTP request and may be able to execute operating-system commands.
The perimeter is not the only exposure boundary
A switch does not have to expose its management interface directly to the internet to be at risk. Any compromised workstation, unmanaged device, guest network, remote-access session or poorly segmented administration host may give an attacker the local position needed to reach it.
GreyNoise reported observing exploitation against 996 Zyxel switches in 48 countries before the vulnerability entered CISA’s Known Exploited Vulnerabilities catalogue. That count describes devices from which the researchers observed successful exploitation and data removal. It should not be expanded into a claim about the total number of victims or the full campaign size.
CISA’s entry marks ransomware use as unknown and requires forensic triage. It does not name an actor, publish a universal indicator set or say that every GS1900 device is reachable in the same way.
What network teams should do before Thursday
- Find every GS1900 switch. Include branch sites, labs, temporary deployments and devices administered by local teams rather than central networking.
- Record the exact model and firmware. Use Zyxel’s advisory to match each device to the fixed release rather than assuming that a nearby model number has the same status.
- Restrict the management plane. Permit access only from dedicated administration networks and named management systems.
- Review the vulnerable period. Look for unexpected HTTP requests to the management interface, configuration changes, new accounts, command execution and outbound connections from the switch.
- Preserve evidence before rebuilding. Export the running configuration, logs and relevant network telemetry when compromise is suspected.
- Rotate exposed secrets. Credentials, SNMP communities, API keys and certificates held by a compromised switch should be treated as potentially exposed.
The federal deadline is not automatically a legal deadline for every organisation. Active exploitation is still a reason to treat CVE-2026-7273 as an incident-response question as well as a patching task.
Sources
- CISA Known Exploited Vulnerabilities catalogue, entry added 21 September 2026 with a 24 September due date.
- Zyxel security advisory for affected GS1900 models and fixed firmware.
- GreyNoise threat report, published 21 September 2026.


