There is no confirmation in the available evidence that attackers are exploiting the newly disclosed Zyxel GS1900 switch vulnerability, CVE-2026-7273. Zyxel’s June 16, 2026 advisory confirms the affected product family and vulnerability, but a disclosure is not proof of exploitation. Separately, CISA lists a different Zyxel flaw, CVE-2025-21391, as known exploited, and an NVD record marks exploitation of the older firewall flaw CVE-2023-33010 as active and automatable. Those records do not establish that CVE-2026-7273—or every recently disclosed Zyxel flaw—is being attacked.
What is known about the newly disclosed Zyxel vulnerability?
The clearest match for a recent Zyxel product disclosure is CVE-2026-7273, a stack-based buffer overflow affecting the GS1900 series of switches. Zyxel dated its advisory June 16, 2026. The advisory index is a disclosure and remediation directory; it does not, by itself, report active exploitation of this CVE.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Zyxel Cyber Security Firewall | Up to 5 Users | Dual-WAN | USGLITE60AX | $189.99 | Buy on Amazon |
This distinction matters: a vulnerability can be serious and require prompt remediation without there being public evidence that attackers are exploiting it. As of October 1, 2026, the available evidence does not confirm in-the-wild exploitation of CVE-2026-7273.
Which Zyxel vulnerabilities have exploitation evidence?
Public records support exploitation claims for two other Zyxel CVEs, not for the GS1900 issue. They affect different product families and should not be treated as one attack campaign.
#1 Best Overall
- WITH 1-YEAR ELITE PACK INCLUDED – New devices registered on or after January 19, 2026 receive complimentary comprehensive web filtering, advanced Nebula Pro features, and enhanced ransomware protection for 12 months. Previously registered devices are not eligible
- ENTERPRISE-GRADE SECURITY WITH DUAL-WAN INTELLIGENCE – Real-time threat intelligence with IPS and anti-malware delivers wire-speed protection, while smart traffic distribution ensures optimal bandwidth usage and uninterrupted connectivity for critical business applications
- AX6000 WIFI 6 READY WITH 2X 2.5G MULTI-GIG PORTS – Dual-band support with seamless Zyxel mesh capability provides far-reaching wireless coverage, while multi-gig Ethernet enables high-speed WAN/LAN connectivity without re-cabling
- CLOUD MANAGEMENT MADE SIMPLE – Set up in minutes via Nebula mobile app and manage your entire network from a single centralized cloud platform without additional hardware controllers or software
- SUSTAINABLE DESIGN – Constructed with up to 95% post-consumer recycled plastics, reduced packaging, and eco-friendly inks to minimize carbon footprint and environmental impact
| CVE | Affected product and issue | Exploitation evidence | Patch or firmware details |
|---|---|---|---|
| CVE-2026-7273 | Zyxel GS1900 series switches; stack-based buffer overflow, according to Zyxel’s June 16, 2026 advisory. | The advisory index does not confirm exploitation. | Use the matching Zyxel advisory for the affected model and remediation instructions; a fixed version is not stated in the available advisory-index information. |
| CVE-2025-21391 | Multiple Zyxel DSL CPE devices; post-authentication command injection through a crafted HTTP request, according to CISA’s catalog description. | Included in CISA’s Known Exploited Vulnerabilities catalog, which identifies vulnerabilities exploited in the wild. | A fixed version is not stated in the available CISA catalog result. Check Zyxel’s matching advisory for remediation. |
| CVE-2023-33010 | Multiple Zyxel firewalls; buffer-overflow vulnerabilities referenced by a Zyxel advisory. | NVD’s record includes CISA Coordinator metadata marking exploitation active and automatable, with total technical impact. This evidence concerns this older CVE only. | A fixed version is not stated in the available NVD record summary. Check Zyxel’s advisory for remediation. |
CISA describes its KEV catalog as an authoritative list of vulnerabilities exploited in the wild. Its entry for CVE-2025-21391 says the attacker must be authenticated. NVD’s exploitation metadata for CVE-2023-33010 is likewise specific to that vulnerability. Neither record proves exploitation of CVE-2026-7273 or the other 2026 disclosures.
Which other Zyxel products have 2026 advisories?
Zyxel’s security-advisory index lists 2026 disclosures dated from May through August across several product families. The entries include:
- CVE-2026-14818: path traversal in the configuration-file execution CLI command of ZLD firewalls.
- CVE-2026-6837 and CVE-2026-8508: command injection and improper authentication affecting certain access points, FWA7 devices and security routers.
- CVE-2026-6952: post-authentication command injection affecting certain DSL/Ethernet CPE devices, fiber ONTs and wireless extenders.
- CVE-2026-7273: stack-based buffer overflow in the GS1900 series of switches.
These descriptions identify different flaws, product families and—in some cases—authentication requirements. The available advisory-index information does not establish active exploitation for these 2026 entries.
How to check whether your Zyxel device is affected
- Identify the exact device. Record its model, hardware revision and installed firmware version. A product-family name alone may not be enough to determine whether a particular device is affected.
- Find the matching Zyxel security advisory. Search Zyxel’s security-advisory index by CVE or product family, then compare the advisory’s affected-device information with your device.
- Follow that advisory’s fix instructions. Install the fixed firmware version if Zyxel specifies one for your model. If the advisory gives different instructions or directs owners to support, follow those instead. The available information here does not specify fixed firmware versions, so do not assume one version applies across Zyxel products.
- Confirm the result. Check the device’s reported firmware version after updating and compare it with the advisory’s stated fix. If you cannot establish that the device is covered by a fix, contact Zyxel support or your administrator.
What to block or restrict while remediation is pending
Reduce exposure until you have applied the relevant fix. In particular, restrict management access from the internet and disable remote administration and UPnP if they are not needed and you can do so without disrupting essential operations. These are interim risk-reduction measures, not a substitute for the advisory’s remediation.
Free tools Windows power users keep installed
One-click scans. No signup required.
Where practical, limit the device’s network exposure while you verify or apply the fix. Avoid changing access controls without understanding their effect on network operations, especially on devices that support critical connectivity.
Should you replace a Zyxel GS1900 switch?
Replacement is a practical option if your switch is outside vendor support or cannot receive the remediation specified for its model. If Zyxel provides a supported fix for your exact hardware revision, follow the advisory rather than assuming the entire GS1900 family must be replaced. The relevant decision is whether your specific device can be brought to a supported, fixed state.
What to monitor for signs of compromise
Review available device and network records for activity that is unexpected for your environment, including:
- Administrative logins you do not recognize.
- Configuration changes that were not authorized.
- Unexpected command execution.
- Outbound connections that do not match normal device behavior.
The available sources do not publish a current indicator-of-compromise list for the newest 2026 Zyxel advisories. These checks can help identify suspicious activity, but the absence of an alert or listed indicator does not prove that a device is uncompromised.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

