CISA Added Zyxel Switch Flaw to KEV Catalog

Federal agencies must secure affected Zyxel GS1900 devices by September 24, 2026.

Updated on Sept. 22, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stylized metallic network switch, representing critical infrastructure cybersecurity policy.
The Cybersecurity and Infrastructure Security Agency has added a critical buffer overflow vulnerability in Zyxel GS1900 network switches to its catalog of known exploited threats. AI Illustration. Upload story photo >

Live Poll

Do you trust that the software you use for business is secure from cyberattacks?

The Cybersecurity and Infrastructure Security Agency has added a critical stack-based buffer overflow vulnerability in Zyxel GS1900 switches to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-7273, allows unauthenticated attackers to execute arbitrary OS commands.

Why it matters

Adding this vulnerability to the KEV catalog mandates that federal agencies address the security risk immediately to prevent potential network compromise. This action highlights the ongoing threat posed by hardware vulnerabilities that allow for remote code execution.

The Zyxel GS1900 vulnerability, CVE-2026-7273, carries a CVSS score of 8.8 and is triggered via crafted HTTP requests. Separately, the Veeam Agent for Windows vulnerability, CVE-2026-32996, has a CVSS score of 7.3.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is the lead federal agency for protecting critical infrastructure in the United States.

Zyxel

Zyxel is a global networking company that manufactures switches and other hardware for enterprise and home use.

Veeam

Veeam is a software company that specializes in data backup, disaster recovery, and data management solutions.

The details

Attackers can compromise the Zyxel switches by sending a malicious HTTP request to the device. Additionally, the Veeam Agent vulnerability is exploited by reading elevated session UIDs stored in a local log file, which can grant an attacker SYSTEM-level control.

Timeline

  1. June 2026: Zyxel issued its initial security advisory.

  2. September 21, 2026: CISA added the switch flaw to its KEV catalog.

  3. September 24, 2026: Deadline for federal agencies to apply firmware fixes.

The Tech Race

The CISA catalog update follows the enforcement pattern established by Binding Operational Directive 22-01, which mandates that federal agencies remediate known exploited vulnerabilities within strict timelines. This process is essential for securing aging network infrastructure against evolving remote code execution threats.

Administrators of Zyxel GS1900 series switches should prioritize firmware updates immediately to prevent unauthorized command execution on their networks. Users should also ensure Veeam backup software is patched to prevent local privilege escalation risks.

The takeaway

Maintaining up-to-date firmware on networking hardware is a critical defense against attackers leveraging known vulnerabilities. Organizations should regularly audit their software and hardware for active exploits to maintain a robust security posture.

Further reading

For more on how government agencies track emerging threats, visit the Cybersecurity section.

Live Poll

Do you trust that the software you use for business is secure from cyberattacks?