Jessica Entwistle
September 22 2026
The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-7273, a stack-based buffer overflow vulnerability affecting Zyxel GS1900 series network switches, to its Known Exploited Vulnerabilities catalogue. CISA reports that the vulnerability is being actively exploited in the wild, and has set a deadline for US federal agencies to apply mitigations. The flaw allows an attacker to execute arbitrary code on affected devices, potentially giving them persistent access to network infrastructure. Zyxel GS1900 switches are commonly used in small to medium-sized business and enterprise environments, making this a relevant risk for organisations that rely on this hardware for network segmentation, access control or operational connectivity.
While CISA's directive applies to US federal agencies, the inclusion of a vulnerability in the KEV catalogue is a strong signal that exploitation is occurring and that organisations globally should prioritise remediation. For UK businesses using Zyxel network equipment, this is a prompt to check whether affected models are in use, whether patches or firmware updates are available, and whether network segmentation and monitoring are sufficient to detect or contain compromise if devices cannot be immediately updated. Network infrastructure is often overlooked in patching programmes, but compromised switches can provide attackers with visibility across internal traffic, the ability to intercept credentials, and a foothold for lateral movement. The vulnerability also highlights the importance of asset management: many organisations do not have a complete inventory of network devices, making it difficult to identify where vulnerable equipment is deployed. This is particularly true for infrastructure that was installed years ago, may not be centrally managed, or sits in remote offices, operational technology environments or legacy networks. Organisations that have strong asset management, regular firmware update processes and network monitoring in place are better positioned to respond quickly when vulnerabilities like this are disclosed.
Check whether Zyxel GS1900 series switches are in use across your organisation, including in branch offices, operational technology environments or legacy networks that may not be centrally managed. Review whether patches or firmware updates are available from Zyxel and prioritise applying them, particularly for devices that are internet-facing or sit on network segments that handle sensitive traffic. If patching cannot be completed immediately, consider whether network segmentation, access controls or monitoring can reduce the risk of exploitation or detect suspicious activity. Review how network infrastructure is included in vulnerability management programmes, ensuring that switches, routers, firewalls and other devices are inventoried, monitored for security updates, and included in regular patching cycles. This is also a prompt to ensure that network devices are configured securely, with default credentials changed, unnecessary services disabled, and management interfaces restricted to trusted networks. Consider whether monitoring is in place to detect unusual traffic patterns, unauthorised configuration changes or signs of compromise on network infrastructure, and ensure that incident response plans account for the possibility that network devices may be targeted or compromised.
Source: CISA