CVE-2026-7273 actively exploited: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities catalogue. It could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Federal agencies must remediate by September 24, 2026.

CISA identified a stack-based buffer overflow in the CGI program of specific Zyxel network equipment. An unauthenticated attacker with local network access could potentially execute OS commands by sending a crafted HTTP request. The agency added this flaw, designated CVE-2026-7273, to its Known Exploited Vulnerabilities catalogue. It remains uncertain whether ransomware actors have used this specific vulnerability in campaigns. Zyxel GS1900 Series Switches are the affected products listed in the advisory. Federal agencies face a strict deadline to address this risk. Stakeholders must evaluate each asset's internet exposure to determine the level of threat. Organizations operating these switches on their local networks face the potential for unauthorized command execution. Vendors share mitigation instructions that operators should apply to remediate the issue. CISA requires federal agencies to remove the vulnerability by September 24, 2026. Operators must comply with BOD 26-04 guidance for prioritizing security updates based on risk. If no mitigations exist, users should discontinue using the affected product entirely.