highOther

CISA KEV Addition: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273)

First seen Sep 22, 2026 · Updated Sep 22, 2026

CISAKEVZyxelbuffer-overflownetwork-deviceswitchBOD-26-04vulnerability-management

CISA has added CVE-2026-7273, a stack-based buffer overflow vulnerability in Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities catalog based on confirmed evidence of active exploitation. Federal agencies are required under BOD 26-04 to remediate this vulnerability on publicly exposed assets, and CISA encourages all organizations to prioritize patching given the active exploitation status.

Technical Analysis

CVE-2026-7273 is a stack-based buffer overflow vulnerability affecting Zyxel GS1900 Series managed switches, a class of vulnerability that typically allows an attacker to corrupt stack memory via crafted input to a network service or management interface, potentially leading to remote code execution or device takeover. The KEV listing indicates confirmed in-the-wild exploitation, and BOD 26-04 flags this vulnerability as one that can grant total control of the affected asset post-exploitation. As a network infrastructure device, exploitation could enable lateral movement, traffic interception, or network segmentation bypass within an environment. Organizations that run AI agent infrastructure, RAG pipelines, or LLM tool-use stacks on networks served by these switches could face exposure if compromised switches are used to intercept or manipulate traffic to/from agent hosts, exfiltrate API keys or credentials in transit, or pivot to servers running agent workloads, making this agent-relevant for enterprises with affected Zyxel switches on the same network segment as AI infrastructure.

Affected Systems

Zyxel GS1900 Series managed switches (specific firmware versions not detailed in source; organizations should consult Zyxel's security advisory for exact affected models/firmware)

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided in source data

Remediation Steps

  1. 1

    Patch/Update Firmware

    Apply the latest firmware update from Zyxel for GS1900 Series switches that addresses CVE-2026-7273 as soon as it is available.

  2. 2

    Restrict Management Interface Exposure

    Ensure switch management interfaces are not exposed to the public internet; restrict access to trusted internal networks or VPN only.

  3. 3

    Follow BOD 26-04 Guidance

    FCEB agencies must remediate per CISA's Binding Operational Directive 26-04 timelines; all organizations should treat KEV-listed vulnerabilities as high priority.

  4. 4

    Compromise Assessment

    Per BOD 26-04 expectations, check whether the system was compromised prior to patching, including reviewing logs and configuration changes on affected switches.

  5. 5

    Network Segmentation Review

    Review network segmentation to limit blast radius if a switch is compromised, particularly for segments hosting AI agent servers, RAG pipelines, or credential stores.

CVE / Advisory IDs

CVE-2026-7273

Industries Most Exposed

GovernmentCritical InfrastructureEnterprise ITTelecommunicationsAny organization using Zyxel GS1900 switches

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.