CISA Added Zyxel Switch Flaw to KEV Catalog
Federal agencies must secure affected Zyxel GS1900 devices by September 24, 2026.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you trust that the software you use for business is secure from cyberattacks?
The Cybersecurity and Infrastructure Security Agency has added a critical stack-based buffer overflow vulnerability in Zyxel GS1900 switches to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-7273, allows unauthenticated attackers to execute arbitrary OS commands.
Why it matters
Adding this vulnerability to the KEV catalog mandates that federal agencies address the security risk immediately to prevent potential network compromise. This action highlights the ongoing threat posed by hardware vulnerabilities that allow for remote code execution.
The Zyxel GS1900 vulnerability, CVE-2026-7273, carries a CVSS score of 8.8 and is triggered via crafted HTTP requests. Separately, the Veeam Agent for Windows vulnerability, CVE-2026-32996, has a CVSS score of 7.3.
The players
CISA
The Cybersecurity and Infrastructure Security Agency is the lead federal agency for protecting critical infrastructure in the United States.
Zyxel
Zyxel is a global networking company that manufactures switches and other hardware for enterprise and home use.
Veeam
Veeam is a software company that specializes in data backup, disaster recovery, and data management solutions.
The details
Attackers can compromise the Zyxel switches by sending a malicious HTTP request to the device. Additionally, the Veeam Agent vulnerability is exploited by reading elevated session UIDs stored in a local log file, which can grant an attacker SYSTEM-level control.
Timeline
June 2026: Zyxel issued its initial security advisory.
September 21, 2026: CISA added the switch flaw to its KEV catalog.
September 24, 2026: Deadline for federal agencies to apply firmware fixes.
The Tech Race
The CISA catalog update follows the enforcement pattern established by Binding Operational Directive 22-01, which mandates that federal agencies remediate known exploited vulnerabilities within strict timelines. This process is essential for securing aging network infrastructure against evolving remote code execution threats.
Administrators of Zyxel GS1900 series switches should prioritize firmware updates immediately to prevent unauthorized command execution on their networks. Users should also ensure Veeam backup software is patched to prevent local privilege escalation risks.
The takeaway
Maintaining up-to-date firmware on networking hardware is a critical defense against attackers leveraging known vulnerabilities. Organizations should regularly audit their software and hardware for active exploits to maintain a robust security posture.
Further reading
For more on how government agencies track emerging threats, visit the Cybersecurity section.
Live Poll
Do you trust that the software you use for business is secure from cyberattacks?










