CISA Adds Zyxel Switch Vulnerability to KEV Catalog Amid Active Exploitation
CISA has added CVE-2026-7273, a stack-based buffer overflow vulnerability in Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting Zyxel GS1900 Series Switches to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, identified as CVE-2026-7273, is a stack-based buffer overflow that has been observed under active exploitation by malicious cyber actors.
This inclusion in the KEV Catalog signifies that CISA has confirmed evidence of real-world attacks leveraging this flaw. Such vulnerabilities are considered high-risk because they can provide attackers with significant control over affected systems, posing a substantial threat to organizational security. The nature of stack-based buffer overflows often allows attackers to overwrite critical memory regions, potentially leading to arbitrary code execution.
As a result of this addition, federal civilian executive branch (FCEB) agencies are now mandated by Binding Operational Directive (BOD) 26-04 to prioritize the remediation of CVE-2026-7273 on any publicly exposed assets. This directive emphasizes a risk-based approach to vulnerability management, requiring agencies to address vulnerabilities that offer complete control post-exploitation with urgency.
BOD 26-04 also mandates that federal agencies assess whether systems were compromised before applying patches, a crucial step in understanding the full impact of an exploit. While the directive specifically targets FCEB agencies, CISA strongly encourages all organizations, including those in the private sector, to adopt similar risk-based vulnerability management practices.
The KEV Catalog serves as a vital resource for organizations seeking to understand and mitigate the most pressing cyber threats. CISA continuously monitors threat intelligence and actively adds vulnerabilities to the catalog when evidence of exploitation emerges, ensuring that organizations can focus their limited resources on the most critical security updates.
Organizations are urged to consult CISA's KEV Catalog for the latest information on exploited vulnerabilities and to implement timely patching and mitigation strategies. CISA also provides a nomination form for the public to submit evidence of exploited vulnerabilities not yet listed in the catalog, provided they have a CVE ID, proof of exploitation, and clear mitigation guidance.
The addition of CVE-2026-7273 to the KEV Catalog underscores the persistent threat posed by vulnerabilities in network infrastructure devices. These devices, often overlooked in security assessments, can serve as critical entry points for attackers seeking to infiltrate networks or disrupt operations.