The Cybersecurity and Infrastructure Security Agency issued orders over the weekend of 28 September 2026 directing all US government agencies to patch two critical Citrix NetScaler vulnerabilities by Wednesday. The flaws are being actively exploited in attacks.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-7273, a high-severity vulnerability in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog on September 22, 2026. Attackers are actively exploiting the flaw for data theft, prompting federal agencies to patch by September 25.