Zyxel security advisory (AV26-603) – Update 1
Canada's Cyber Centre says Zyxel GS1900 buffer overflow CVE-2026-7273 is now in CISA's KEV catalog.
The Canadian Centre for Cyber Security updated advisory AV26-603 after CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog on September 21, 2026. Zyxel first published the advisory on June 16, 2026, for vulnerabilities in multiple versions and models of GS1900 series switches. The listed issue is a stack-based buffer overflow. The Cyber Centre urges administrators to review Zyxel's advisory and CISA's KEV entry and apply updates.
- CVE-2026-7273 is a stack-based buffer overflow in GS1900 switches.
- CISA added the flaw to the KEV catalog on September 21, 2026.
- Zyxel's original advisory covering multiple GS1900 versions dates to June 16, 2026.
Vulnerabilities mentionedAll →
- CVE-2026-72738.83%Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerabilitypublished · Zyxel GS1900 Series Switches KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article91 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-603
Date: June 16, 2026
Updated: September 21, 2026
On June 16, 2026, Zyxel published a security advisory to address vulnerabilities in the following products:
- GS1900 series switches – multiple versions and models
Update 1
On September 21, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/zyxel-security-advisory-av26-603