CISA Adds a Zyxel Switch Flaw to the KEV Catalog Under BOD 26-04
On September 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added one vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series switches. Binding Operational Directive (BOD) 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk KEV listings on publicly exposed assets that can grant total control after exploitation, and it sets expectations for checking whether threat actors compromised a system before a patch was applied. CISA encourages all organizations to prioritize KEV remediation.
Why it matters: This is an immediate vulnerability-operations and compliance workload signal for CIOs and CISOs responsible for internet-facing network gear.
Everett, Massachusetts: City Hall Cyber Incident and Official Reopen Path
Per the City of Everett’s official notice, City Hall closed to the public after a cybersecurity incident discovered around 6:30 p.m. on Sunday, September 6, 2026, that impacted the city’s internal network and technology systems. Police, fire, public works, schools, and libraries continued to operate as normal, and third-party online bill payment systems remained available. An official city update dated September 17, 2026 stated that City Hall would reopen Monday, September 21.
Why it matters: Municipal cyber incidents create continuity and transparency pressure even when essential services stay online. City and shared-services leaders should treat the reopen timeline as a recovery milestone, not the end of the investigation.
Illinois EO 2026-07 Creates a Statewide AI Cabinet
On September 22, 2026, Illinois Governor JB Pritzker issued Executive Order 2026-07 establishing the Illinois Artificial Intelligence Cabinet. The Cabinet is charged with assessing AI risks to residents and critical infrastructure, developing policies to prepare for and respond to AI incidents, and protecting public assets. It includes senior leaders from the Department of Innovation and Technology, emergency management and homeland security, financial and professional regulation, the commerce commission, state police, public health, and environmental protection. The Governor will appoint members within thirty days of the order’s effective date. The Cabinet sunsets no later than December 31, 2027.
Why it matters: This is a concrete same-day state governance structure for AI risk, incident preparedness, and public-asset protection that state CIOs and CISOs should map to their own control frameworks.
FAA Unveils SMART, an AI-Supported Airspace Management Tool
On September 21, 2026, the Federal Aviation Administration unveiled Strategic Management of Airspace, Routes and Trajectories (SMART). The platform centralizes about 200 data streams, including weather patterns, flight paths, traffic flow, and controller staffing metrics, and uses an AI-supported engine to help anticipate congestion and weather constraints. The FAA began limited use around Washington, D.C., and plans gradual expansion. SMART recommendations are reviewed by FAA staff, and the agency states the tool cannot replace air traffic controllers or take over control of an aircraft.
Why it matters: Federal mission AI is moving into live operational use with an explicit human-review pattern. That governance model is relevant beyond aviation for any high-consequence decision support system.
GSA OneGov Expands Discounted ChatGPT Access for Governments
The U.S. General Services Administration announced a OneGov agreement with OpenAI for discounted, consumption-based access to ChatGPT models. The 27-month offer is expected to take effect October 1, 2026, with a 50% discount on token-based usage, including environments authorized under the Federal Risk and Authorization Management Program, and with no platform-access fee or minimum spend. Eligible buyers include federal, state, local, and tribal governments.
Why it matters: October 1 is an acquisition and governance deadline. Agencies that can buy must also be ready to control data handling, use cases, and spend before consumption ramps.
Sources
CISA KEV alerthtps://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
City of Everett official City Hall cyber notice and reopen update:
https://cityofeverett.com/city-hall-to-close-tuesday-sept-8-due-to-cybersecurity-incident/
Boston 25 News (Tier 3 corroboration on reopen coverage, 2026-09-21):
https://www.boston25news.com/news/local/everett-city-hall-reopens-after-cybersecurity-incident-forced-weeks-long-closure/4IO5KKYZU5DXRIWN5OKXUFP6RU/
Illinois Executive Order 2026-07 (HTML):
https://www.illinois.gov/government/executive-orders/executive-order.executive-order-2026-07.2026.html
Illinois Executive Order 2026-07 (PDF):
https://www.illinois.gov/content/dam/soi/en/web/illinois/documents/government/executive-orders/2026/executive-order-2026-07-english.pdf
FAA SMART announcement (2026-09-21):
https://www.faa.gov/newsroom/trumps-transportation-secretary-sean-p-duffy-delivers-state-art-air-traffic-control
GSA OneGov OpenAI ChatGPT release (2026-09-10; effective 2026-10-01):
https://www.gsa.gov/about-gsa/newsroom/news-releases/gsa-expands-onegov-ai-offerings-with-discounted-openais-chatgpt-09102026
Topics We’re Tracking (But Didn’t Make the Cut)
GAO-26-108439 ATC spoofing
- CISA/NIST IR 8587
- California EO N-9-26 AI kill switch
- Maryland AI framework
- Riverside city AI working group
That’s The Exchange for today. Remember: Guesswork isn’t a strategy. We’ll see you next time for the five minutes that secure your next twenty-four hours.
The Exchange Daily and Weekly deliver verified public-source intelligence for executive decision-makers. All information is from reputable, publicly available sources. Every effort is made to keep details accurate as of publication time, but readers should always confirm time-sensitive items such as policy changes, budget figures, and timelines with official documents and briefings. Always validate with primary sources before action.
The Exchange Daily and the Exchange Weekly do not constitute legal, investment, procurement, security, compliance, or technical advice. Content is for informational purposes only.
The Exchange Daily and Weekly are a production of Metora Solutions LLC, a HUBZone and Service Disabled Veteran Owned Small Business. All rights reserved. Copyright Metora Solutions LLC 2026.
