CVE-2026-7273
CISA Adds One Known Exploited Vulnerability to Catalog
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Coverage 2 sources
-
2026-09-21
CISA Cybersecurity Advisories
high
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2026-7273, a stack-based buffer overflow vulnerability in Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities Catalog.
-
2026-09-22
Help Net Security
high
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor exploited CVE-2026-7273 in 996 Zyxel GS1900 switches across 48 countries.
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands