A stack-based buffer overflow vulnerability, identified as CVE-2026-7273, in Zyxel GS1900 Series Switches is now confirmed to be actively exploited in the wild. The vulnerability affects firmware versions through 2.90(ABTQ.1)C0 of the GS1900-48HPv2 model.
The flaw, which carries a CVSS score of 8.8, allows an unauthenticated attacker on the local area network (LAN) to potentially execute operating system commands by sending a specially crafted HTTP request. The vulnerability was publicly disclosed on June 16, 2026.
Evidence of active exploitation emerged 97 days after disclosure, with the vulnerability being added to multiple known exploited vulnerability (KEV) catalogs on September 21, 2026. These include the U.S. CISA KEV, the European Union Agency for Cybersecurity (ENISA) EUVD, and the commercial VulnCheck KEV. The Computer Incident Response Center Luxembourg (CIRCL) also mirrors these listings.
CISA has issued a directive requiring federal agencies to apply vendor-recommended mitigations or discontinue use of affected products by September 24, 2026, in accordance with its BOD 26-04 guidance on prioritizing security updates.
Public reports collected from VulnCheck and CIRCL, dating back to September 21, 2026, also indicate active exploitation. One such report references "open season on Kapibala attacker steal," though the specifics of this attack are not detailed. The Zyxel security advisory for this vulnerability is available on their global support website.






