CISA Adds Exploited Zyxel Switch Flaw to Catalog
PUBLISHED Sep 22, 2026, 11:09 AM ET
Read, Watch or Listen
The Cybersecurity and Infrastructure Security Agency officially updated its Known Exploited Vulnerabilities catalog to include a high-severity flaw impacting Zyxel GS1900 series network switches. Designated as CVE-2026-7273, the stack-based buffer overflow is currently facing active exploitation in the wild. Federal civilian agencies are now under a binding operational directive to apply necessary patches by mid-October 2026 to mitigate device compromise risks. This security update highlights the ongoing focus on defending enterprise hardware against active exploitation vectors. Administrators managing affected Zyxel network equipment should immediately verify firmware versions and apply vendor-supplied remediation patches to protect against potential network intrusions.
By Shahbaz A. | JQJO News
Timeline of Events
- On June 16 2026 Zyxel issued a security advisory and patches for a stack-based buffer overflow vulnerability (CVE-2026-7273) affecting GS1900 series switch firmware versions through 2.90.
- On June 16 2026 CVE-2026-7273 was officially published to the National Vulnerability Database (NVD) with a CVSS severity score of 8.8.
- 2026-08 — Threat actors actively exploited CVE-2026-7273 in the wild, targeting Zyxel GS1900 switches across multiple countries to exfiltrate sensitive network configurations and hashed credentials.
- On September 21 2026 The Cybersecurity and Infrastructure Security Agency (CISA) formally added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog following confirmed active exploitation.
- On October 12 2026 Federal civilian executive branch agencies are mandated by CISA operational directives to apply necessary firmware patches to vulnerable Zyxel switches.
News Intelligence
- Immediate US impact: Federal civilian agencies operating affected Zyxel networking hardware are bound by strict operational deadlines to deploy vendor-supplied security patches.
- Possible long-term US impact: The enforcement highlights heightened federal oversight regarding unpatched hardware vulnerabilities across critical enterprise supply chains.
- Most affected groups: Network administrators, federal IT security teams, and organizations deploying Zyxel GS1900 series smart managed switches.
- Reader priority: High
Center: No NEWS outlet is framing the story in a materially distinct ideological way.
CISA Adds One Known Exploited Vulnerability to Catalog https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
Coverage of Story:
From Left
No left-leaning sources found for this story.
From Center
CISA Adds One Known Exploited Vulnerability to Catalog
Cybersecurity and Infrastructure Security AgencyFrom Right
No right-leaning sources found for this story.
Comments