CISA Added Zyxel Switch Flaw to Exploited Catalog

Federal agencies must patch CVE-2026-7273 by September 24, 2026, to prevent arbitrary command execution.

Updated on Sept. 22, 2026 in Cybersecurity

Isometric editorial illustration of a dark gray network switch unit with port rows, representing critical infrastructure cybersecurity policy.
CISA added the CVE-2026-7273 vulnerability in Zyxel GS1900 series switches to its Known Exploited Vulnerabilities catalog on September 21, 2026. AI Illustration. Upload story photo >

Live Poll

Do you trust that the software you use for business is secure from cyberattacks?

CISA added a critical Zyxel GS1900 series switch vulnerability to its Known Exploited Vulnerabilities catalog on September 21, 2026. The flaw, designated CVE-2026-7273, allows unauthenticated remote attackers to execute arbitrary commands.

Why it matters

Adding this vulnerability to the catalog mandates immediate remediation for federal civilian agencies to mitigate active exploitation risks. The move underscores the increasing focus on securing network infrastructure against remote command execution.

CVE-2026-7273 carries a CVSS score of 8.8, reflecting its high severity compared to the 7.3 rating assigned to the Veeam Agent vulnerability, CVE-2026-32996.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is the lead U.S. federal agency responsible for protecting critical infrastructure and managing the KEV catalog.

Zyxel

A networking hardware manufacturer that produces enterprise-grade switches and firmware solutions.

The details

The Zyxel vulnerability is a stack-based buffer overflow, a memory corruption error where a program writes more data to a buffer than it can hold, allowing attackers to overwrite adjacent memory. Attackers trigger this by sending a specifically crafted HTTP request to the target switch. Separately, CVE-2026-32996 allows for local privilege escalation in Veeam Agent by reading elevated session UIDs from a local log file, granting an attacker SYSTEM-level control.

Timeline

  1. June 2026: Zyxel released the initial security advisory.

  2. September 21, 2026: CISA added the Zyxel flaw to the KEV catalog.

  3. September 24, 2026: Deadline for FCEB agencies to apply fixes.

The Tech Race

The inclusion of this vulnerability in the KEV catalog aligns with the federal government's Binding Operational Directive 22-01, which standardizes remediation timelines for known threats. This effort forces agencies to maintain patching cadences that keep pace with the active exploitation landscape.

Federal civilian agencies must immediately prioritize firmware updates for all deployed Zyxel GS1900 series switches to maintain compliance. Private sector organizations using similar hardware should monitor their own networks for identical indicators of compromise.

The takeaway

This action highlights the persistent risk posed by stack-based buffer overflows in enterprise networking gear. Stakeholders should monitor the CISA Known Exploited Vulnerabilities catalog for future additions to ensure their infrastructure remains compliant with federal standards.

What happens next

Federal agencies are required to apply firmware patches for Zyxel GS1900 switches no later than September 24, 2026.

Further reading

For broader trends in federal vulnerability management, visit Cybersecurity.

Live Poll

Do you trust that the software you use for business is secure from cyberattacks?

CISA Added Zyxel Switch Flaw to Exploited Catalog