CISA Warns of Zyxel GS1900 Switches Flaw Actively Exploited in Attacks
CISA added exploited Zyxel GS1900 buffer overflow CVE-2026-7273 to KEV, warning of unauthenticated command execution.
CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog on September 21, 2026, after confirming active exploitation. The flaw is a critical stack-based buffer overflow (CWE-121) in the CGI program of Zyxel GS1900 Series switches. An unauthenticated attacker on the local network can send a crafted HTTP request and execute operating-system commands on the switch. Federal remediation is due September 24, 2026, under BOD 26-04, which also requires forensic triage; ransomware use has not been confirmed.
- CVE-2026-7273 is a critical stack-based buffer overflow in Zyxel GS1900 CGI.
- Unauthenticated local attackers can run operating-system commands via crafted HTTP requests.
- Added to CISA KEV on September 21, 2026; patch deadline is September 24.
- BOD 26-04 requires forensic triage, not patching alone.
- CISA has not linked the flaw to ransomware campaigns.
Vulnerabilities mentionedAll →
- CVE-2026-72738.83%Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerabilitypublished · Zyxel GS1900 Series Switches KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article411 words · extracted from cybersecuritynews.com · click to collapse
CISA added CVE-2026-7273, a critical stack-based buffer overflow in the CGI program of Zyxel GS1900 Series Switches, to its KEV catalog after confirming active exploitation.
The vulnerability could allow an unauthenticated attacker on the local network to send a specially crafted HTTP request to a vulnerable device.
Successful exploitation may enable the attacker to execute operating-system commands on the affected switch, creating a serious risk for organizations that use the devices in enterprise or operational networks.
Zyxel GS1900 switches are managed network devices, which means a compromise could give an attacker a valuable position inside a target environment.
From a compromised switch, threat actors may attempt to monitor traffic, alter network settings, disrupt connectivity, move laterally, or establish persistence through configuration changes.
Zyxel GS1900 Switches Flaw Exploited
CISA classified the issue under CWE-121, which refers to stack-based buffer overflow weaknesses. Such flaws occur when a program writes more data into a memory buffer than it can safely hold.
Attackers can exploit this condition to overwrite adjacent memory and potentially redirect a program’s execution flow. CISA added CVE-2026-7273 to its catalog on September 21, 2026, with a remediation deadline of September 24, 2026.
Urging affected organizations to apply vendor-provided mitigations under Binding Operational Directive 26-04 (BOD 26-04), which prioritizes security updates based on risk.
CISA also marked the vulnerability as requiring forensic triage under BOD 26-04. This requirement indicates that organizations should not treat remediation as a patch-only event.
Security teams should examine affected switches for signs of unauthorized access, suspicious management activity, unexpected configuration changes, and abnormal HTTP requests targeting the administrative interface.
At present, CISA has not confirmed whether the vulnerability has been used in ransomware campaigns. However, active exploitation and the possibility of unauthenticated command execution make the flaw especially important for defenders.
Attackers frequently target network infrastructure devices because they can provide broad visibility and control after an initial compromise.
Organizations using Zyxel GS1900 Series Switches should identify exposed and internally accessible devices, restrict management interfaces to trusted administrative networks.
Apply Zyxel’s guidance as soon as possible, and review logs for potential exploitation attempts. If mitigations are not available, CISA advises discontinuing use of the affected product.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.