CISA gives Zyxel GS1900 owners a September 24 patch deadline

Zyxel Networks source image; editorial cover for the GS1900 security alert.Zyxel Networks
Zyxel Networks source image; editorial cover for the GS1900 security alert.Zyxel Networks
Tools & Apps

CISA lists CVE-2026-7273 in its Known Exploited Vulnerabilities Catalog with a September 24 remediation deadline; Zyxel has released firmware patches for affected GS1900 switches.

CISA lists CVE-2026-7273 in the Known Exploited Vulnerabilities Catalog with a September 24, 2026 remediation deadline. The issue affects Zyxel GS1900 switches, and Zyxel has released firmware patches for the supported models.

What CVE-2026-7273 exposes

Zyxel describes a stack-based buffer overflow in the CGI program of GS1900-series firmware. A LAN-based, unauthenticated attacker could send a crafted HTTP request and potentially execute operating-system commands on a vulnerable switch. The advisory identifies the vulnerability as CVE-2026-7273.

The CISA catalog marks the entry for federal civilian agencies under its binding operational deadline. For private operators, that deadline is still a useful urgency signal: internet-exposed management interfaces, flat internal networks, and unmanaged branch switches can turn a LAN-only flaw into a practical intrusion path.

Affected GS1900 firmware and available fixes

Zyxel’s advisory lists these affected models and patched versions:

  • GS1900-8: 2.90(AAHH.1)C0 and earlier → 2.90(AAHH.2)C0
  • GS1900-8HP: 2.90(AAHI.1)C0 and earlier → 2.90(AAHI.2)C0
  • GS1900-10HP: 2.90(AAZI.1)C0 and earlier → 2.90(AAZI.2)C0
  • GS1900-16, GS1900-24, GS1900-24E, and GS1900-24EP have corresponding 2.90-series fixes.
  • GS1900-24HPv2, GS1900-48, and GS1900-48HPv2 also have patched firmware listed by Zyxel.

The vendor says products not listed in its table remain unaffected after its investigation. Check the exact model and firmware string before upgrading; do not assume that a similar GS-series name maps to the same image.

What administrators should do today

  1. Inventory GS1900 switches and record model, firmware, management exposure, and network location.
  2. Apply the Zyxel firmware version matching the device model.
  3. Restrict management access to trusted administration networks and remove unnecessary HTTP exposure.
  4. Review switch and adjacent network logs for unexpected management requests or configuration changes.
  5. If patching must wait, isolate the management plane and document the exception until the update is complete.

The catalog entry does not establish that every GS1900 installation has been attacked, and Zyxel’s advisory describes a LAN-based attack surface. Those limits matter when triaging risk, but they do not remove the patch requirement for devices in exposed or poorly segmented environments.

Evidence and deadline

CISA’s catalog sets September 24, 2026 as the remediation date for CVE-2026-7273. Zyxel’s advisory supplies the affected firmware ranges and patch targets. Administrators should use the vendor advisory for the upgrade path and CISA’s catalog for the government remediation status, then verify the running firmware after the reboot.

From reading to doing

Try the related loot

Give Any Model a Sandboxed Shell and File Workspace with OpenRouter

Open loot