CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a critical stack-based buffer overflow in Zyxel GS1900 Series Switches. The flaw resides in the switches' CGI program and allows an unauthenticated attacker on the local network to send a crafted HTTP request and potentially execute operating-system commands.
Federal agencies must remediate the issue by September 24, 2026, under Binding Operational Directive 26-04; CISA also requires forensic triage. Organizations should apply Zyxel's mitigations, restrict switch-management interfaces to trusted administrative networks, assess exposed devices, and review switches and logs for compromise indicators. Organizations unable to mitigate the vulnerability should discontinue use of affected devices; ransomware-campaign use is currently unknown.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CISA released KEV Catalog version 2026.09.21 and added CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel GS1900 Series Switches. The catalog records active exploitation; a local unauthenticated attacker can use a crafted HTTP request to potentially execute operating-system commands, and CISA marked the issue for forensic triage.
Zyxel released firmware updates that remediate CVE-2026-7273 across ten GS1900 Series switch models. The fixes update affected 2.90 firmware branches to their corresponding .2 builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.