U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
CISA added exploited Zyxel GS1900 switch flaw CVE-2026-7273 to the KEV catalog, with a September 24 fix deadline.
CISA added CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel GS1900 series switch firmware, to the Known Exploited Vulnerabilities catalog. The flaw, scored CVSS 8.8, lets an unauthenticated attacker on the local network send a crafted HTTP request and potentially execute operating-system commands. Zyxel patched affected models in 2.90 firmware builds, and federal civilian agencies must remediate by September 24, 2026. CISA did not name attackers; researchers at ISCAS are credited with the report.
- CVE-2026-7273 is a stack-based buffer overflow in Zyxel GS1900 CGI firmware, CVSS 8.8.
- Unauthenticated LAN attackers can run OS commands via a crafted HTTP request.
- Patches are the 2.90 second-release firmware builds for affected GS1900 models.
- Federal agencies must remediate by September 24, 2026, under BOD 22-01.
- CISA named no attackers; ISCAS researchers are credited with the report.
Vulnerabilities mentionedAll →
- CVE-2026-72738.83%Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerabilitypublished · Zyxel GS1900 Series Switches KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article361 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 22, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog.
The flaw is a stack-based buffer overflow that could allow attackers to execute arbitrary operating system commands.
“A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.” reads the advisory.
The vulnerability affects the CGI component of Zyxel’s GS1900 switch firmware. According to Zyxel, an unauthenticated attacker on the local network could exploit the flaw by sending a specially crafted HTTP request and potentially gain the ability to run OS commands on the device.
The vulnerability has been fixed in the following firmware versions:
| Affected model | Affected version | Patch availability |
|---|---|---|
| GS1900-8 | 2.90(AAHH.1)C0 and earlier | 2.90(AAHH.2)C0 |
| GS1900-8HP | 2.90(AAHI.1)C0 and earlier | 2.90(AAHI.2)C0 |
| GS1900-10HP | 2.90(AAZI.1)C0 and earlier | 2.90(AAZI.2)C0 |
| GS1900-16 | 2.90(AAHJ.1)C0 and earlier | 2.90(AAHJ.2)C0 |
| GS1900-24 | 2.90(AAHL.1)C0 and earlier | 2.90(AAHL.2)C0 |
| GS1900-24E | 2.90(AAHK.1)C0 and earlier | 2.90(AAHK.2)C0 |
| GS1900-24EP | 2.90(ABTO.1)C0 and earlier | 2.90(ABTO.2)C0 |
| GS1900-24HPv2 | 2.90(ABTP.1)C0 and earlier | 2.90(ABTP.2)C0 |
| GS1900-48 | 2.90(AAHN.1)C0 and earlier | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | 2.90(ABTQ.1)C0 and earlier | 2.90(ABTQ.2)C0 |
CISA did not disclose technical details about the attacks exploiting this issue or who is behind them.
Zyxel credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS with finding and reporting the flaw. At the time of writing, Zyxel had not updated its advisory to confirm whether the vulnerability was being actively exploited.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw by September 24, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)