Junglewise Threat Intelligence

CVE-2026-7273: Zyxel GS1900 Series stack-based buffer overflow in CGI program

CVE-2026-7273 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2026-06-16

Vendors: Zyxel.

Executive brief

Zyxel GS1900 Series Switches are network switches used in corporate and government environments to manage data traffic. A stack-based buffer overflow flaw in these devices allows attackers to remotely take complete control of the switch without authentication, enabling data interception, network disruption, or lateral movement into protected networks. The vulnerability is actively being exploited by threat actors, making immediate patching critical for organizations using these devices.

Technical details

CVE-2026-7273 is a stack-based buffer overflow vulnerability in the Zyxel GS1900 Series Switches that permits remote code execution. The vulnerability likely results from insufficient input validation in a network-facing service or management interface that accepts untrusted data and writes it to fixed-size stack buffers. Attack is likely network-based and may not require prior authentication. Successful exploitation grants an attacker complete control of the affected switch, allowing arbitrary command execution and system compromise. CISA has confirmed active exploitation in the wild and added the vulnerability to the Known Exploited Vulnerabilities catalog; organizations should check for and apply vendor patches immediately.

Affected products

  • Zyxel GS1900 Series Switches

Timeline

  • 2026-09-21: kev added: Added to CISA KEV Catalog based on evidence of active exploitation

References