thehackernews.com 10 Sept 2026, 10:36 UTC

CISA Flags Cisco, Citrix and Fortinet Flaws Under Active Attack

CISA has added three actively exploited flaws to the Known Exploited Vulnerabilities (KEV) catalog, affecting Cisco, Citrix, and Fortinet products, with a deadline of 12 September 2026 for Federal Civilian Executive Branch (FCEB) agencies to apply patches.

The vulnerabilities are CVE-2026-20079, a highly critical authentication bypass in Cisco Secure Firewall Management Center (FMC) that could enable an unauthenticated remote attacker to bypass authentication and run script files to gain root access; CVE-2026-19490, an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway when configured as AAA virtual server or

Gateway; and CVE-2025-25249, a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager and FortiSASE that could allow remote code execution via crafted requests. CVSS scores on the bulletin range from 7.3 to 10.0. Cisco has also updated its advisory noting active exploitation of CVE-2026-20079 since August 2026, though details remain sparse.

The KEV addition follows heightened high‑risk activity, including a China-linked actor activity around Cisco routers and ongoing NetScaler exploitation observed in honeypots.

Evidence and practical response: the report cites 56 exploitation attempts for CVE-2026-19490 since 3 September 2026, with 36 of those on 8 September 2026, and references PivotC2‑style activity linked to CVE-2025-25249 in Fortinet deployments. SOCRadar describes PivotC2 as a Node[.]js RAT delivered via FortiGate targets that establishes a persistent TLS C2 channel and offers extensive post‑exploitation capabilities.

Organisations using affected products are advised to implement the latest patches, limit exposed internet access, rotate credentials, and conduct indicators‑of‑compromise hunts as part of ongoing mitigation.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline