U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
CISA added exploited Zyxel GS1900 switch flaw CVE-2026-7273 to the KEV catalog, with a September 24 fix deadline.
CISA added CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel GS1900 series switch firmware, to the Known Exploited Vulnerabilities catalog. The flaw, scored CVSS 8.8, lets an unauthenticated attacker on the local network send a crafted HTTP request and potentially execute operating-system commands. Zyxel patched affected models in 2.90 firmware builds, and federal civilian agencies must remediate by September 24, 2026. CISA did not name attackers; researchers at ISCAS are credited with the report.