Zyxel has confirmed that a flaw in its GS1900 series of managed network switches — affordable, widely used hardware that many small and mid-sized businesses run their office networks on — is being actively exploited. The bug, tracked as CVE-2026-7273 (CVSS 8.8), is a stack-based buffer overflow in the switch's web management software. It lets an attacker on the local network run operating-system commands without ever logging in, simply by sending a specially crafted request to the device's web interface.
Threat intelligence firm GreyNoise says it has been tracking an ongoing campaign, likely run by a Chinese-speaking group, that has already compromised close to 1,000 GS1900 switches across 48 countries. Once inside a switch, the attackers use built-in file-transfer tools and disguised scripts to pull down its configuration file, its stored (hashed) admin credentials, and details about the wider network it manages — reconnaissance that can support a deeper intrusion later. Zyxel actually shipped a firmware fix for this flaw back in June, months before the active exploitation came to light, which is why CISA added it to its Known Exploited Vulnerabilities catalog this week and ordered US federal agencies to patch it by Thursday.
What this means for your business
If your office network runs on Zyxel GS1900 switches — check the label on the unit or ask whoever manages your network — the fix has already been available for months, so this is a "go apply it now" problem rather than a "wait for a patch" one. Log into each switch's admin interface, check the firmware version against Zyxel's advisory for CVE-2026-7273, and update any that are behind. While you're in there, make sure the switch's web management interface is only reachable from a trusted internal network or management VLAN, not left open to every device on the LAN or, worse, the internet — this flaw only needs local network access to work, so segmentation limits who can reach it in the first place. If you don't manage your own network hardware, this is a good prompt to ask your IT provider directly whether any Zyxel switches on your network have been checked against this advisory.