Stack-Based Buffer Overflow in Zyxel GS1900 Switches (CVE‑2026‑7273) Added to CISA KEV Catalog
What It Is – A stack‑based buffer overflow in Zyxel GS1900 series Ethernet switches (CVE‑2026‑7273) allows an unauthenticated attacker to execute arbitrary code and gain full control of the device. CISA has confirmed active exploitation and placed the flaw in its Known Exploited Vulnerabilities (KEV) catalog.
Exploitability – Exploits are observed in the wild; the vulnerability is publicly disclosed and no patch was available at the time of the advisory. CVSS v3.1 is not published yet, but the impact is rated high because successful exploitation yields total device takeover.
Affected Products – Zyxel GS1900 series managed switches (all firmware versions prior to the forthcoming security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a vulnerability‑management control that continuously inventories assets, tracks KEV listings, and prioritizes remediation based on risk.
- Provides a concrete audit‑ready evidence point: organizations that can show timely patching of a KEV item can substantiate due‑diligence to regulators and enterprise customers.
- Highlights the importance of continuous monitoring of public threat feeds (CISA KEV, vendor advisories) to keep control evidence up‑to‑date.
Recommended Actions
- Identify every publicly‑exposed Zyxel GS1900 switch in your environment.
- Apply Zyxel’s security patch as soon as it is released; if unavailable, implement compensating network‑segmentation controls.
- Record remediation status in your vulnerability‑management system and map the activity to the “Vulnerability Management & Patch Prioritization” control objective.
- Update your audit evidence repository (e.g., Verisq Trust Center) to reflect the remediation for future assessments.
Source: CISA Advisory – 2026‑09‑21