← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 22, 2026 · 09:13via Security Affairs

U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

Brief

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog.

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8. 8), to its Known Exploited Vulnerabilities (KEV) catalog .

The flaw is a stack-based buffer overflow that could allow attackers to execute arbitrary operating system commands.

“A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.” reads the advisory .

The vulnerability affects the CGI component of Zyxel’s GS1900 switch firmware.

Read more on Security Affairs