CISA adds a patched Zyxel GS1900 series switch vulnerability, CVE-2026-7273 (CVSS 8.8), to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence that it is actively exploited. The flaw is a stack-based buffer overflow in the switch’s web management CGI component, and successful exploitation allows an unauthenticated attacker with local network access to execute operating-system commands.

The reported technical impact is command execution with high potential for confidentiality, integrity, and availability compromise. Since switches occupy the network control position, an attacker who gains command execution can potentially alter VLAN and port configurations, read the running configuration (which may include credentials), modify routing, and pivot across segments the switch forwards or bridges. A separate article discusses potential post-exploitation changes such as creating local accounts, altering SNMP settings, and persisting malicious changes via startup configuration.

Coverage is aligned on the core facts: CISA’s KEV designation and active exploitation; the CGI/web-management trigger; and the availability of fixed firmware for listed GS1900 models. The sources differ mainly in emphasis—one focuses on CISA’s catalog action and the vulnerability’s general severity, while the other provides more detail on attacker capabilities, affected-model versions, and practical detection and mitigation approaches.