CISA KEV Addition: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273)
First seen Sep 22, 2026 · Updated Sep 22, 2026
CISA has added CVE-2026-7273, a stack-based buffer overflow vulnerability in Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities catalog based on confirmed evidence of active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on publicly exposed assets, and CISA encourages all organizations to prioritize patching given the active exploitation status.
Technical Analysis
CVE-2026-7273 is a stack-based buffer overflow vulnerability affecting Zyxel GS1900 Series managed switches, a class of vulnerability that typically allows an attacker to corrupt stack memory via crafted input to a network service or management interface, potentially leading to remote code execution or device takeover. The KEV listing indicates confirmed in-the-wild exploitation, and BOD 26-04 flags this vulnerability as one that can grant total control of the affected asset post-exploitation. As a network infrastructure device, exploitation could enable lateral movement, traffic interception, or network segmentation bypass within an environment. Organizations that run AI agent infrastructure, RAG pipelines, or LLM tool-use stacks on networks served by these switches could face exposure if compromised switches are used to intercept or manipulate traffic to/from agent hosts, exfiltrate API keys or credentials in transit, or pivot to servers running agent workloads, making this agent-relevant for enterprises with affected Zyxel switches on the same network segment as AI infrastructure.
Affected Systems
Zyxel GS1900 Series managed switches (specific firmware versions not detailed in source; organizations should consult Zyxel's security advisory for exact affected models/firmware)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source data
Remediation Steps
- 1
Patch/Update Firmware
Apply the latest firmware update from Zyxel for GS1900 Series switches that addresses CVE-2026-7273 as soon as it is available.
- 2
Restrict Management Interface Exposure
Ensure switch management interfaces are not exposed to the public internet; restrict access to trusted internal networks or VPN only.
- 3
Follow BOD 26-04 Guidance
FCEB agencies must remediate per CISA's Binding Operational Directive 26-04 timelines; all organizations should treat KEV-listed vulnerabilities as high priority.
- 4
Compromise Assessment
Per BOD 26-04 expectations, check whether the system was compromised prior to patching, including reviewing logs and configuration changes on affected switches.
- 5
Network Segmentation Review
Review network segmentation to limit blast radius if a switch is compromised, particularly for segments hosting AI agent servers, RAG pipelines, or credential stores.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.