CISA orders feds to patch Zyxel flaw exploited for data theft
CISA has added CVE-2026-7273, an actively exploited stack-based buffer overflow in ZyXEL GS1900 switches, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply fixes by Thursday. Crafted HTTP requests can allow an unauthenticated attacker on the LAN to execute operating-system commands, creating a path to device compromise and data theft. GreyNoise reports that a suspected Chinese-speaking actor exploited the flaw to steal data from 996 ZyXEL switches across 48 countries; organizations using affected GS1900 models should update to Zyxel's patched firmware releases.