Our takeCISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to the KEV catalog. It's confirmed exploited in the wild. Patch now if you run these switches.Cyber Resilience desk
Sources (4)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- cccs · cccs
- securityweek · securityweek
What this means for you — Security leader:CISA added CVE-2026-7273 (Zyxel GS1900 series stack-based buffer overflow) to the KEV catalog; exploitation is confirmed. Patch or apply the vendor mitigations immediately per BOD 22-01 and your risk-based prioritization.
What this means for you — Lean IT orgs:If you run a Zyxel GS1900 series switch on your local network, update its firmware right away using the instructions from Zyxel. This is a confirmed exploited vulnerability that lets an attacker on your network run commands.
What this means for you — MSP:Check every client for Zyxel GS1900 series switches and apply the firmware update or mitigations immediately. This CVE is now in CISA KEV with confirmed in-the-wild exploitation.
What this means for you — Researcher:CISA added CVE-2026-7273 for the Zyxel GS1900 series stack-based buffer overflow to the KEV catalog. Exploitation is confirmed; Zyxel advisory AV26-603 and firmware updates are available.