CISA Warns of Zyxel GS1900 Switches Flaw Actively Exploited in Attacks
CISA added exploited Zyxel GS1900 buffer overflow CVE-2026-7273 to KEV, warning of unauthenticated command execution.
CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog on September 21, 2026, after confirming active exploitation. The flaw is a critical stack-based buffer overflow (CWE-121) in the CGI program of Zyxel GS1900 Series switches. An unauthenticated attacker on the local network can send a crafted HTTP request and execute operating-system commands on the switch. Federal remediation is due September 24, 2026, under BOD 26-04, which also requires forensic triage; ransomware use has not been confirmed.