ON 21 September 2026, US authorities confirmed active exploitation of CVE-2026-7273, a high-severity stack-based buffer overflow in Zyxel GS1900-series switches. The vulnerability has a CVSS v3 score of 8.8 and affects firmware version 2.90 and earlier across models including the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24HPv2, GS1900-48 and GS1900-48HPv2.
The article says the flaw has been added to CISA’s Known Exploited Vulnerabilities catalogue, although no publicly available proof-of-concept code has been confirmed.
According to Zyxel’s advisory, the defect is in a CGI programme used by the switches’ web management interface. An unauthenticated attacker on the local network can send a specially crafted HTTP request that triggers memory corruption by exceeding the stack buffer’s boundary. Successful exploitation could allow arbitrary operating-system commands to run with elevated privileges, potentially giving an attacker control of the switch and visibility into connected networks.
Federal civilian agencies were given until 24 September 2026 to apply the relevant vendor fixes. Administrators should install Zyxel’s latest firmware and restrict management access to trusted IP addresses or dedicated VLANs, rather than exposing the interface to untrusted local segments.