The Cybersecurity and Infrastructure Security Agency (CISA) has flagged a newly identified critical vulnerability in Zyxel’s GS1900 switch series—labeled CVE-2026-7273. This stack-based buffer overflow flaw affects the switches’ CGI program and has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog after confirmation that it’s been actively exploited. The agency issued guidance on how to respond in order to safeguard network integrity.
The Risk and How Attackers Are Using It
This bug allows an unauthenticated attacker connected to the local network to send a crafted HTTP request to a device running a vulnerable Zyxel GS1900 switch. From there, they could execute operating-system commands on the switch. Such breaches give threat actors significant control, enabling them to intercept traffic, alter configurations, disrupt connectivity, move laterally through networks, or embed themselves persistently. These risks are especially severe for environments that rely on GS1900 switches in enterprise or operational infrastructure.
CISA has classified this issue under CWE-121, the category for stack-based buffer overflows, which can cause programs to overwrite memory beyond allocated boundaries and hijack execution flow. The vulnerability was formally added to CISA’s KEV list on September 21, 2026, with a remediation deadline of September 24, 2026.
Mitigation, Detection, and What Organizations Should Do
The agency urges all organizations using GS1900 switches to apply vendor-provided fixes immediately and follow the requirements of Binding Operational Directive 26-04 (BOD 26-04), which tailors updates based on organizational risk. Where mitigation patches aren’t yet available, CISA suggests discontinuing use of the affected devices.
Beyond patching, CISA isn’t treating this as a simple update event—vulnerable systems should undergo forensic review for indicators of compromise. That includes scanning logs for unexpected HTTP requests targeting administrative functions, unusual management activity, or configuration changes that weren’t authorized. Limiting administrative access to trusted networks also serves as a key defense.
While there’s no public confirmation that this flaw has been tied to ransomware attacks so far, the fact that it allows unauthenticated command execution and already being used in active assaults makes it a high-priority threat. Network infrastructure devices are especially prized by attackers, as compromising one can offer a strategic foothold across an organization.
Organizations should inventory which devices are exposed—internally or over the internet—confine admin interfaces to trusted subnets, act on Zyxel’s mitigation guidance, and monitor switches for anomalous behavior. Removing or replacing affected units may be necessary in environments where remediations are delayed.
This vulnerability underscores a broader problem: even devices considered “low-profile,” like network switches, can expose major security gaps when exploited. What’s needed now is proactive defense—timely patching, vigilant monitoring, and strict control of admin access. As attackers continue to target networking hardware, GS1900 users must treat this alert as a top operational priority.