CISA put Zyxel GS1900 on KEV. GreyNoise already counted 996 switches in 48 countries.
CVE-2026-7273 is unauthenticated OS command execution on the CGI. Vendor scored it LAN. Patch firmware, then hunt default admin. Federal due date is Thursday.
Bottom line up front
CONFIRMED CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog on 21 September 2026. Catalog version 2026.09.21 (released 21 September 18:46 UTC, count 1717). It is the only new row since the [Linux kernel trio](/posts/2026-09-19-linux-kernel-kev-ktls-ebtables-afalg/) on 18 September. Federal due date is 24 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes.
The product is the Zyxel GS1900 smart-managed Gigabit access-switch family. The bug is a stack-based buffer overflow in the CGI program (CWE-121). Zyxel’s June advisory, which CISA still cites, says a LAN-based, unauthenticated attacker can send a crafted HTTP request and potentially execute OS commands. Zyxel’s CNA score is 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD has not published its own vector. Firmware that closes it shipped 16 June 2026. As of this morning Zyxel has not revised the advisory to say the bug is exploited.
Do not collapse three facts.
- Adjacent is not “safe.”
AV:Ameans the attacker needs a path to the management CGI. GreyNoise’s count is what you get when that CGI is on the internet, on a VPN that is not the LAN you think it is, or on a guest/IoT VLAN the operator never treated as hostile. - The victim set is already measured. GreyNoise (Andrew Thompson, Mark Mager, 21 September) reported a suspected Chinese-speaking malicious cyber actor that exploited GS1900 units on or about 17 August 2026 and exfiltrated configurations, hashed root credentials, and network information from 996 switches in 48 countries. That is the first public in-the-wild write-up of this CVE. CISA’s KEV row is the federal confirmation; it does not name the campaign.
- Patching without asking who still has
adminis incomplete. GreyNoise: 564 of those 996 still had factory-default credentials. Hashed root is not the same as a unique password.
This is not a re-run of [yesterday’s Jade Sleet Daily Top](/posts/2026-09-21-jade-sleet-it-services-flatroof-roofdeck/). Different product, different clock, different access class.
| Fact | Record |
|---|---|
| CVE | CVE-2026-7273 |
| Product | Zyxel GS1900 series (8/10/16/24/48-port smart-managed, including PoE SKUs) |
| KEV catalog | 2026.09.21, count 1717 |
| Added / due | 21 September / 24 September 2026 |
| Vendor patch | 16 June 2026, 2.90(*.2)C0 per model |
| Exploitation | CONFIRMED as KEV; GreyNoise campaign CONFIRMED as their telemetry |
| Ransomware use | Unknown |
| Named CISA actor | None |
| OT / process impact | None claimed |
What happened
Zyxel published the CGI overflow on 16 June 2026 and credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo of ISCAS. The June text is still the vendor record: overflow in the CGI, LAN, no authentication, crafted HTTP, potential OS command execution. Patches are the 2.90(….2)C0 builds. Zyxel’s table (and the BleepingComputer reprint this morning):
| Affected model | Affected version | Fixed version |
|---|---|---|
| GS1900-8 | 2.90(AAHH.1)C0 and earlier | 2.90(AAHH.2)C0 |
| GS1900-8HP | 2.90(AAHI.1)C0 and earlier | 2.90(AAHI.2)C0 |
| GS1900-10HP | 2.90(AAZI.1)C0 and earlier | 2.90(AAZI.2)C0 |
| GS1900-16 | 2.90(AAHJ.1)C0 and earlier | 2.90(AAHJ.2)C0 |
| GS1900-24 | 2.90(AAHL.1)C0 and earlier | 2.90(AAHL.2)C0 |
| GS1900-24E | 2.90(AAHK.1)C0 and earlier | 2.90(AAHK.2)C0 |
| GS1900-24EP | 2.90(ABTO.1)C0 and earlier | 2.90(ABTO.2)C0 |
| GS1900-24HPv2 | 2.90(ABTP.1)C0 and earlier | 2.90(ABTP.2)C0 |
| GS1900-48 | 2.90(AAHN.1)C0 and earlier | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | 2.90(ABTQ.1)C0 and earlier | 2.90(ABTQ.2)C0 |
Zyxel’s June note: on-market products not in that table remain unaffected. Do not inventory “every Zyxel switch.” Do inventory every GS1900 still on 2.90(*.1) or earlier.
CISA’s 21 September alert names this one CVE. The JSON row matches: vendor Zyxel, product GS1900 Series Switches, CWE-121, notes point at the June advisory, BOD 26-04, and the forensics-triage guidance. This is Zyxel’s 13th KEV CVE. The previous twelve are older CPE, firewall, NAS, and router rows, not this switch family.
GreyNoise’s 21 September report is the public exploitation narrative CISA did not write. Timeline they published:
| When | What | Status |
|---|---|---|
| 16 Jun 2026 | Zyxel advisory and patches | CONFIRMED vendor |
| ~17 Aug 2026 | MCA exploits GS1900, pulls a collector over TFTP, stages loot | CONFIRMED GreyNoise |
| 17 Sep 2026 | GreyNoise: first public in-wild case; not yet KEV | CONFIRMED their statement at publication |
| 21 Sep 2026 | GreyNoise blog; CISA KEV 2026.09.21 | CONFIRMED |
| 22 Sep 2026 | BleepingComputer / The Hacker News English amplification | CONFIRMED secondary |
| 24 Sep 2026 | FCEB due date | CONFIRMED catalog |
Post-exploit, as GreyNoise reconstructed it from the actor’s tooling: a TFTP get of a collector script, then a copy of gathered data to a web-reachable path on the switch (/home/web/tmp/info.txt). RWP is not republishing the exploit script, the PyArmor wrapper, or the command-line flags. Defenders need the collection behavior, not a reproduction.
Country counts GreyNoise published (top of 996): Italy 133, United States 129, Taiwan 123, France 90, South Korea 69, Netherlands 66, Czech Republic 49, United Kingdom 33. The long tail runs to 48 countries. Treat those as GreyNoise’s victim geography, not a CISA attribution.
Why it matters
GS1900 is the cheap managed access layer in branches, clinics, warehouses, schools, and a lot of plants that never bought a Cisco Catalyst. PoE SKUs sit under cameras, phones, and APs. A switch that will run OS commands is a place to read configs, persist a credential, alter VLANs, or cut PoE. That is network-plane impact. It is not, on this evidence, a PLC or a process.
The CVSS vector is the operational trap. Teams that file AV:A under “needs to be on the LAN” will skip internet-exposed management, cellular-backed cameras on the same L2, and MSP jump hosts. GreyNoise’s 996 is the counter-example. The right question is “can an unauthenticated HTTP client reach the CGI,” not “does NVD say adjacent.”
The default-credential slice is the second trap. More than half of the collected switches still had factory defaults. Firmware without a unique admin password is a second, independent finding. BOD 26-04’s forensic-triage language applies before you declare the patch the closure.
KEV on a three-day clock, after a June patch, means the unpatched tail is the incident class. The bug is not new. The catalog row is.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
GS1900 models in Zyxel’s June table, firmware 2.90(*.1)C0 and earlier | In scope for CVE-2026-7273 | CONFIRMED vendor |
Same models on 2.90(*.2)C0 | Patch claimed by vendor; still hunt if management was reachable | CONFIRMED patch; compromise UNKNOWN unless you look |
| GS1900 management CGI reachable from untrusted networks | Highest-leverage exposure; matches GreyNoise collection | ASSESSED from vendor vector + GreyNoise geography |
| Other Zyxel switch families | Not this CVE | CONFIRMED vendor “not listed = unaffected” for on-market |
| Factory-default admin | Independent finding; 564/996 in GreyNoise set | CONFIRMED GreyNoise for that set only |
| Named victim orgs | Not published | UNKNOWN |
| OT / ICS / water / process | Not claimed | No evidence |
| CISA ransomware field | Unknown | CONFIRMED catalog |
Technical context
RWP is not reproducing HTTP bodies, offset tables, or the GOT-versus-stack modes in the actor’s script.
What the primary records actually give defenders:
- Primitive. Unauthenticated HTTP to the GS1900 CGI. Successful overflow → OS command execution. Vendor and CISA both stop at that sentence.
- Prerequisite. Network reachability to the management interface. No account required. No user interaction.
- Collection, this campaign. GreyNoise: TFTP pull of a collector, loot staged under the switch web tree. Configs, hashed root, network facts. Not a claimed implant family unique to GS1900.
- Credentials. Hashed root plus a large default-password subset. Vendor user guides for this series have documented the factory admin account for years. Rotate it. Do not treat hash dump as “no login possible.”
- Campaign, not this CVE. GreyNoise ties the operator to a broader 2026 set (UniFi, WordPress wp2shell, Gitea, others) and says the actor is the same or related to Red Heron as reported by Acronis, on overlapping C2, malware family, and the July Gitea wave. That is GreyNoise’s cluster, not a CISA statement, and it is not proof that every GS1900 victim was in the WordPress 18,000-record theft. Do not merge those incidents.
ATT&CK mapping for what is stated:
- Exploit public-facing application (T1190) when the CGI is reachable from an untrusted network.
- Command execution on a network device (T1059 class).
- Automated collection / exfiltration of device config (T1119 / T1041 class), per GreyNoise.
- Valid accounts (T1078) where factory defaults remain.
Follow-on that is not claimed: ransomware-Known, a named APT in the KEV row, VLAN/PoE sabotage, or traffic interception as observed tradecraft.
Threat / exploitation status
| Claim | Status | Basis |
|---|---|---|
In KEV, added 21 Sep, due 24 Sep, catalog 2026.09.21 count 1717 | CONFIRMED | CISA alert + JSON |
| Exploitation in the wild | CONFIRMED as KEV criterion | CISA |
| 996 switches / 48 countries / ~17 Aug start | CONFIRMED as GreyNoise telemetry | GreyNoise 21 Sep |
| First public in-wild write-up | CONFIRMED as GreyNoise’s claim as of 17 Sep | GreyNoise; CISA does not name them |
| Vendor advisory updated for exploitation | No as of this morning | BC, THN |
| Ransomware use | Unknown | Catalog field |
| Forensic triage required | Yes | Catalog field |
| Actor identity | ASSESSED Chinese-speaking MCA, possibly Red Heron-related | GreyNoise; not independently re-derived |
| LLM-written tooling | ASSESSED by GreyNoise from code-comment patterns | Not proven |
| OT / physical-process impact | Not claimed | No evidence |
High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 8.8 adjacent vector, June patch table, forensic-triage flag, ransomware Unknown, Zyxel’s 13 KEV CVEs, GreyNoise’s 996 / 564 / country table as their measurements. Moderate confidence that internet-reachable management is the dominant real-world condition (geography of 996; no full internet census). Low confidence on CISA’s unpublished exploitation evidence, on Red Heron as a firm identity for the switch work, and on any victim beyond GreyNoise’s unlabeled set.
What defenders should do
- Inventory GS1900, not “Zyxel.” Model, firmware string, management IP, and whether HTTP/HTTPS to the CGI is reachable from anywhere that is not the dedicated out-of-band network. Include MSP-managed closets, camera VLANs, and lab switches. Record internet exposure for BOD 26-04.
- **Patch to the
2.90(*.2)C0build for that SKU, then reboot onto it.** Confirm the running firmware, not the file you downloaded. If the box is out of Zyxel’s vulnerability-support window and has no row in the June table, replace it; do not invent a backport.
- Treat reachable management as a compromise-until-proven-otherwise problem. CISA’s required action includes forensics-triage language. Before you call the ticket closed: export running config, check for unexpected users, compare firmware and boot image, look for unexpected files under the web temp path GreyNoise named, and pull authentication logs if the box still has them. Factory-default admin is a finding even on a patched switch.
- Move the CGI off untrusted networks. Management VRF or OOB. No WAN NAT to 80/443 on the switch. No shared VLAN with cameras and guests. Adjacent scoring assumes you already did this. GreyNoise’s count says many people did not.
- Hunt the campaign only as campaign, not as this CVE. GreyNoise’s broader IOC table (backdoor hashes,
*.981666.xyz, staging74.48.66[.]73, accountskapibala/kapibala2) is for the operator’s other jobs. Do not declare a GS1900 clean because those hashes are absent. Do not declare a WordPress host related because a GS1900 was collected.
- Sequence the rest of the federal list. The [Linux kernel trio](/posts/2026-09-19-linux-kernel-kev-ktls-ebtables-afalg/) was due yesterday. [Cisco ISE CVE-2026-76460](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/) and [SEG CVE-2026-76461](/posts/2026-09-15-cisco-seg-cve-2026-76461-sqli/) are already this month’s identity-plane tops. [vCenter CVE-2026-59310](/posts/2026-09-16-vmware-vcenter-cve-2026-59310-ransomware/) remains ransomware-Known. CVE-2026-7273 is the new three-day clock.
This is not an exploitation guide. Use the vendor firmware table and the management-plane inventory.
RWP assessment
Score 8.5. CISA put a June CGI RCE on a Thursday clock. GreyNoise had already counted 996 collected switches, more than half still on factory defaults, with the United States second in their table. That is a better-evidenced network-device KEV than most 9.8s that ship with no victim geography.
It outranks Arctic Wolf’s CVE-2026-32996 Veeam Agent local SYSTEM (public PoC 14 September; local; not KEV). It outranks WordPress CVE-2026-93485 Comment2Shell (7.1.1 on 17 September; admin session required; THN: no in-wild, not KEV). It outranks Bishop Fox’s Veeam Service Provider Console chain (CVE-2026-58073 / CVE-2026-58072, research on an August 9.3.0 patch, no confirmed exploitation this window). It outranks the Colorado water-utility OT reports (late-August events, unnamed private systems serving fewer than 200 people, foreign actors unconfirmed, no water-quality impact) as a daily — that is a process-manipulation story for the weekly OT book, not a KEV with a 24 September due date. [Jade Sleet](/posts/2026-09-21-jade-sleet-it-services-flatroof-roofdeck/) is yesterday.
The failure mode to sand down is “adjacent, so we are fine” and its twin, “we patched in June.” If the CGI still answers on an address you do not control, you are in GreyNoise’s denominator. If admin is still the factory account, you were in it twice.
What we are watching
- Whether Zyxel revises the June advisory to acknowledge exploitation.
- Whether CISA names a campaign or flips ransomware-use off Unknown.
- Whether 996 was a one-wave collection or the actor is still hitting unpatched CGI.
- Distro of remaining internet-reachable GS1900 management after Thursday.
- CVE-2026-32996 Veeam Agent: exploitation claims without a KEV row.
- Any attempt to treat a collected access switch at an industrial tenant as an OT event without process evidence.
Sources
- CISA — Adds one KEV (CVE-2026-7273) (21 September 2026)
- CISA KEV JSON feed
- CISA Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Zyxel — GS1900 stack-based buffer overflow (16 June 2026)
- NVD — CVE-2026-7273
- CVE.org — CVE-2026-7273
- GreyNoise — Open Season on Kapibala (21 September 2026)
- BleepingComputer — CISA orders feds to patch Zyxel flaw by Thursday (22 September 2026)
- The Hacker News — Zyxel and Veeam flaws under active exploitation (22 September 2026)
- INCIBE — GS1900 buffer overflow (16 June 2026)
- [RWP Daily Top, 21 September 2026 — Jade Sleet](/posts/2026-09-21-jade-sleet-it-services-flatroof-roofdeck/)
- [RWP Daily Top, 19 September 2026 — Linux kernel KEV trio](/posts/2026-09-19-linux-kernel-kev-ktls-ebtables-afalg/)
- [RWP Daily Top, 17 September 2026 — Cisco ISE CVE-2026-76460](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/)
- [RWP Daily Top, 16 September 2026 — vCenter CVE-2026-59310](/posts/2026-09-16-vmware-vcenter-cve-2026-59310-ransomware/)
Sources
- CISA — Adds one KEV CVE-2026-7273
- CISA — KEV JSON feed catalog 2026.09.21
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Zyxel — GS1900 stack-based buffer overflow advisory CVE-2026-7273
- NVD — CVE-2026-7273
- CVE — CVE-2026-7273
- GreyNoise — Open Season on Kapibala
- BleepingComputer — CISA orders feds to patch Zyxel GS1900 by Thursday
- The Hacker News — Zyxel and Veeam flaws under active exploitation
- INCIBE — GS1900 buffer overflow advisory