CISA added CVE-2026-7273, a critical stack-based buffer overflow in the CGI program of Zyxel GS1900 Series Switches, to its KEV catalog after confirming active exploitation.
The vulnerability could allow an unauthenticated attacker on the local network to send a specially crafted HTTP request to a vulnerable device.
Successful exploitation may enable the attacker to execute operating-system commands on the affected switch, creating a serious risk for organizations that use the devices in enterprise or operational networks.
Zyxel GS1900 switches are managed network devices, which means a compromise could give an attacker a valuable position inside a target environment.
From a compromised switch, threat actors may attempt to monitor traffic, alter network settings, disrupt connectivity, move laterally, or establish persistence through configuration changes.
Zyxel GS1900 Switches Flaw Exploited
CISA classified the issue under CWE-121, which refers to stack-based buffer overflow weaknesses. Such flaws occur when a program writes more data into a memory buffer than it can safely hold.
Attackers can exploit this condition to overwrite adjacent memory and potentially redirect a program’s execution flow. CISA added CVE-2026-7273 to its catalog on September 21, 2026, with a remediation deadline of September 24, 2026.
Urging affected organizations to apply vendor-provided mitigations under Binding Operational Directive 26-04 (BOD 26-04), which prioritizes security updates based on risk.
CISA also marked the vulnerability as requiring forensic triage under BOD 26-04. This requirement indicates that organizations should not treat remediation as a patch-only event.
Security teams should examine affected switches for signs of unauthorized access, suspicious management activity, unexpected configuration changes, and abnormal HTTP requests targeting the administrative interface.
At present, CISA has not confirmed whether the vulnerability has been used in ransomware campaigns. However, active exploitation and the possibility of unauthenticated command execution make the flaw especially important for defenders.
Attackers frequently target network infrastructure devices because they can provide broad visibility and control after an initial compromise.
Organizations using Zyxel GS1900 Series Switches should identify exposed and internally accessible devices, restrict management interfaces to trusted administrative networks.
Apply Zyxel’s guidance as soon as possible, and review logs for potential exploitation attempts. If mitigations are not available, CISA advises discontinuing use of the affected product.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
The post CISA Warns of Zyxel GS1900 Switches Flaw Actively Exploited in Attacks appeared first on Cyber Security News.
