← All briefings

CISA Adds a Zyxel Switch Flaw to the KEV Catalog Under BOD 26-04

On September 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added one vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series switches. Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk KEV listings on publicly exposed assets that can grant total control after exploitation, and it sets expectations for checking whether threat actors compromised a system before a patch was applied. CISA encourages all organizations to prioritize KEV remediation.

Why it matters: This is an immediate vulnerability-operations and compliance workload signal for CIOs and CISOs responsible for internet-facing network gear.

Everett, Massachusetts: City Hall Cyber Incident and Official Reopen Path

Per the City of Everett’s official notice, City Hall closed to the public after a cybersecurity incident discovered around 6:30 p.m. on Sunday, September 6, 2026, that impacted the city’s internal network and technology systems. Police, fire, public works, schools, and libraries continued to operate as normal, and third-party online bill payment systems remained available. An official city update dated September 17, 2026 stated that City Hall would reopen Monday, September 21.

Why it matters: Municipal cyber incidents create continuity and transparency pressure even when essential services stay online. City and shared-services leaders should treat the reopen timeline as a recovery milestone, not the end of the investigation.

Illinois EO 2026-07 Creates a Statewide AI Cabinet

On September 22, 2026, Illinois Governor JB Pritzker issued Executive Order 2026-07 establishing the Illinois Artificial Intelligence Cabinet. The Cabinet is charged with assessing AI risks to residents and critical infrastructure, developing policies to prepare for and respond to AI incidents, and protecting public assets. It includes senior leaders from the Department of Innovation and Technology, emergency management and homeland security, financial and professional regulation, the commerce commission, state police, public health, and environmental protection. The Governor will appoint members within thirty days of the order’s effective date. The Cabinet sunsets no later than December 31, 2027.

Why it matters: This is a concrete same-day state governance structure for AI risk, incident preparedness, and public-asset protection that state CIOs and CISOs should map to their own control frameworks.

FAA Unveils SMART, an AI-Supported Airspace Management Tool

On September 21, 2026, the Federal Aviation Administration unveiled Strategic Management of Airspace, Routes and Trajectories (SMART). The platform centralizes about 200 data streams, including weather patterns, flight paths, traffic flow, and controller staffing metrics, and uses an AI-supported engine to help anticipate congestion and weather constraints. The FAA began limited use around Washington, D.C., and plans gradual expansion. SMART recommendations are reviewed by FAA staff, and the agency states the tool cannot replace air traffic controllers or take over control of an aircraft.

Why it matters: Federal mission AI is moving into live operational use with an explicit human-review pattern. That governance model is relevant beyond aviation for any high-consequence decision support system.

GSA OneGov Expands Discounted ChatGPT Access for Governments

The U.S. General Services Administration announced a OneGov agreement with OpenAI for discounted, consumption-based access to ChatGPT models. The 27-month offer is expected to take effect October 1, 2026, with a 50% discount on token-based usage, including environments authorized under the Federal Risk and Authorization Management Program, and with no platform-access fee or minimum spend. Eligible buyers include federal, state, local, and tribal governments.

Why it matters: October 1 is an acquisition and governance deadline. Agencies that can buy must also be ready to control data handling, use cases, and spend before consumption ramps.

Sources

CISA KEV alerthtps://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog

City of Everett official City Hall cyber notice and reopen update:

https://cityofeverett.com/city-hall-to-close-tuesday-sept-8-due-to-cybersecurity-incident/

Boston 25 News (Tier 3 corroboration on reopen coverage, 2026-09-21):

https://www.boston25news.com/news/local/everett-city-hall-reopens-after-cybersecurity-incident-forced-weeks-long-closure/4IO5KKYZU5DXRIWN5OKXUFP6RU/

Illinois Executive Order 2026-07 (HTML):

https://www.illinois.gov/government/executive-orders/executive-order.executive-order-2026-07.2026.html

Illinois Executive Order 2026-07 (PDF):

https://www.illinois.gov/content/dam/soi/en/web/illinois/documents/government/executive-orders/2026/executive-order-2026-07-english.pdf

FAA SMART announcement (2026-09-21):

https://www.faa.gov/newsroom/trumps-transportation-secretary-sean-p-duffy-delivers-state-art-air-traffic-control

GSA OneGov OpenAI ChatGPT release (2026-09-10; effective 2026-10-01):

https://www.gsa.gov/about-gsa/newsroom/news-releases/gsa-expands-onegov-ai-offerings-with-discounted-openais-chatgpt-09102026

Topics We’re Tracking (But Didn’t Make the Cut)

That’s The Exchange for today. Remember: Guesswork isn’t a strategy. We’ll see you next time for the five minutes that secure your next twenty-four hours.

The Exchange Daily and Weekly deliver verified public-source intelligence for executive decision-makers. All information is from reputable, publicly available sources. Every effort is made to keep details accurate as of publication time, but readers should always confirm time-sensitive items such as policy changes, budget figures, and timelines with official documents and briefings. Always validate with primary sources before action.

The Exchange Daily and the Exchange Weekly do not constitute legal, investment, procurement, security, compliance, or technical advice. Content is for informational purposes only.

The Exchange Daily and Weekly are a production of Metora Solutions LLC, a HUBZone and Service Disabled Veteran Owned Small Business. All rights reserved. Copyright Metora Solutions LLC 2026.