CISA gives federal agencies three days to patch a Zyxel switch bug already being used in attacks
CVE-2026-7273 lets anyone on the local network hijack GS1900 switches with a single crafted web request. Federal deadline: 24 September 2026.

Key points
- CISA gave US federal agencies until 24 September 2026 to patch a Zyxel switch flaw already being used in real attacks.
- The bug, CVE-2026-7273, carries a CVSS severity score of 8.8 out of 10 and needs no password to exploit.
- Affected kit is the Zyxel GS1900 series network switches, running firmware up to and including 2.90(ABTQ.1)C0.
- An attacker on the same local network can send one specially built web request and run commands on the device.
- CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 21 September 2026.
CISA has told every US federal civilian agency to patch a Zyxel network switch bug by Wednesday. That's an unusually tight window, and it signals the attacks in the wild aren't theoretical.
The flaw sits in the GS1900 series, small managed switches that shuffle traffic between desks and servers inside an office. Zyxel sells them widely to small and mid-sized businesses, and they turn up in branch offices of larger organisations, which is likely how they landed on CISA's radar.
What is the bug?
It's a stack-based buffer overflow in the switch's web management interface, a classic memory-corruption flaw where oversized input overwrites parts of the device's working memory and lets the attacker's data run as code. The official CVE record confirms an unauthenticated attacker on the local network can send a crafted HTTP request and execute operating system commands on the switch. No login required, and no user interaction needed. CVSS 8.8.
The GS1900 series is listed as affected in CISA's catalogue entry. Administrators should move to the fixed firmware Zyxel shipped with its patch.
How bad is 'LAN-based' really?
The attacker has to be on the same local network as the switch. That's not remote-from-the-internet bad, but it's still bad. Anyone who has already phished a single laptop or plugged into a conference-room port can reach it. Once they own the switch, they own the traffic passing through it and have a quiet foothold that survives reboots of everything else.
That's presumably why CISA isn't waiting. The Hacker News, which flagged the KEV addition on Monday, notes CISA cited evidence of active exploitation without naming the group behind it. CISA rarely does. This is the second time in a week we've reported a compressed federal patching window: two days earlier we covered three Linux kernel bugs that agencies had until 21 September to fix.
What should defenders do this week?
Patch, then check. The new Binding Operational Directive 26-04 tells federal agencies to look for signs the box was already broken into before the fix went on, not just to install the update and move on. Private-sector teams should do the same. A compromised switch won't show up in your endpoint tools.
| Item | Detail |
|---|---|
| CVE | CVE-2026-7273 |
| CVSS | 8.8 (High) |
| Affected | Zyxel GS1900 series, firmware through 2.90(ABTQ.1)C0 |
| Added to KEV | 21 September 2026 |
| Federal patch deadline | 24 September 2026 |
Three-day KEV deadlines are the tell. When CISA compresses the usual three-week clock, the exploitation they're seeing is either broad or cheap. If you run GS1900s and were planning to get to this next sprint, don't.



