CISA Adds One Known Exploited Vulnerability to Catalog

Summary

CISA has added CVE-2026-7273, a stack-based buffer overflow vulnerability in Zyxel GS1900 Series Switches, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog.

IFF Assessment

FOE

The addition of a new, actively exploited vulnerability to CISA's KEV catalog represents an increased risk for organizations that do not promptly patch, as it indicates a known avenue for attack.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 24, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must prioritize patching CVE-2026-7273 on Zyxel GS1900 series switches, as it has been confirmed as actively exploited. This highlights the ongoing importance of diligent vulnerability management and timely patching, especially for devices exposed to the internet.

Read Full Story →