Zyxel Network Switch Flaw Added to US Government's Actively Exploited Vulnerability List
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability affecting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw, tracked as CVE-2026-7273, is a stack-based buffer overflow, a type of bug that attackers commonly use to take control of a device remotely. CISA confirmed there is evidence this vulnerability is already being exploited in the wild.
Zyxel GS1900 switches are widely used networking equipment found in small business and office environments to connect computers, servers, and other devices. A successful attack on this type of vulnerability can potentially grant an attacker full control over the switch, which could then be used to intercept traffic, disrupt operations, or pivot further into a business network.
While CISA's directive requiring rapid patching applies only to US federal agencies, the agency encourages all organisations, including small and medium businesses, to treat KEV Catalog entries as high priority and patch them quickly given the confirmed real-world exploitation.