HomeIntelligenceBrief
VULNERABILITY BRIEF 🟠 High Vulnerability

Stack‑Based Buffer Overflow in Zyxel GS1900 Switches (CVE‑2026‑7273) Added to CISA KEV Catalog

CISA has listed CVE‑2026‑7273, a remote code execution flaw in Zyxel GS1900 switches, in its Known Exploited Vulnerabilities catalog. The vulnerability grants attackers full control of the device, prompting organizations to prioritize patching and evidence collection for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Stack-Based Buffer Overflow in Zyxel GS1900 Switches (CVE‑2026‑7273) Added to CISA KEV Catalog

What It Is – A stack‑based buffer overflow in Zyxel GS1900 series Ethernet switches (CVE‑2026‑7273) allows an unauthenticated attacker to execute arbitrary code and gain full control of the device. CISA has confirmed active exploitation and placed the flaw in its Known Exploited Vulnerabilities (KEV) catalog.

Exploitability – Exploits are observed in the wild; the vulnerability is publicly disclosed and no patch was available at the time of the advisory. CVSS v3.1 is not published yet, but the impact is rated high because successful exploitation yields total device takeover.

Affected Products – Zyxel GS1900 series managed switches (all firmware versions prior to the forthcoming security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a vulnerability‑management control that continuously inventories assets, tracks KEV listings, and prioritizes remediation based on risk.
  • Provides a concrete audit‑ready evidence point: organizations that can show timely patching of a KEV item can substantiate due‑diligence to regulators and enterprise customers.
  • Highlights the importance of continuous monitoring of public threat feeds (CISA KEV, vendor advisories) to keep control evidence up‑to‑date.

Recommended Actions

  1. Identify every publicly‑exposed Zyxel GS1900 switch in your environment.
  2. Apply Zyxel’s security patch as soon as it is released; if unavailable, implement compensating network‑segmentation controls.
  3. Record remediation status in your vulnerability‑management system and map the activity to the “Vulnerability Management & Patch Prioritization” control objective.
  4. Update your audit evidence repository (e.g., Verisq Trust Center) to reflect the remediation for future assessments.

Source: CISA Advisory – 2026‑09‑21

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →