Find notable cyber news and cases, enriched with sources, timelines, and signals.

Zyxel GS1900 series switches stack-based buffer overflow security flaw (CVE-2026-7273)

Vulnerability
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-7273 in Zyxel GS1900 series switches is now in CISA’s KEV catalog after evidence of active exploitation, putting affected networks at risk of arbitrary OS command execution via a crafted HTTP request.

Timeline

  1. 22.09.2026 08:31 2 articles · 2h ago

    CISA adds CVE-2026-7273 in Zyxel GS1900 switches to KEV after active exploitation

    Initial Disclosure

    CISA added CVE-2026-7273 affecting Zyxel GS1900 series switches to the Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. Zyxel said the stack-based buffer overflow in the CGI program of the switch firmware could let a LAN-based, unauthenticated attacker send a crafted HTTP request to execute OS commands, and the vendor had released fixes for GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48, and GS1900-48HPv2. Federal Civilian Executive Branch (FCEB) agencies were required to apply the fixes by September 24, 2026.

    Show sources