CISA adds the Zyxel GS1900 switch flaw to KEV and sets a September 24 patch deadline
On September 21, 2026, CISA added CVE-2026-7273, a stack-based buffer overflow in the CGI of Zyxel GS1900 switches, to its KEV catalog after confirming active exploitation. Lock down the management interface, apply Zyxel’s fix before September 24, and hunt for signs of compromise on exposed devices.