CISA has added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Zyxel GS1900 Series Switches and is a stack-based buffer overflow in the devices’ CGI programme that may allow command execution.
An unauthenticated attacker on the local area network can exploit the flaw by sending a crafted HTTP request. Successful exploitation could allow the attacker to execute operating system commands. The vulnerability has a CVSS score of 8.8 and is rated High. Patch availability is currently unknown.
CISA has confirmed active exploitation, as reflected by the KEV listing. The available data does not confirm use in ransomware campaigns. CISA set a remediation deadline of 24 September 2026.
CISA requires organisations to apply mitigations in accordance with Zyxel’s instructions and comply with BOD 26-04 and its Forensics Triage Requirements. FCEB agencies must meet these requirements, evaluate each asset’s internet exposure and discontinue use if mitigations are unavailable. All organisations should review their exposure to affected switches.
See the NVD entry and CISA KEV catalogue for full details.