securityaffairs.com 10 Sept 2026, 18:57 UTC

CISA Flags Four Actively Exploited Flaws Including Cisco Zero Day

CISA Flags Four Actively Exploited Flaws Including Cisco Zero Day

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four flaws from Cisco, Google Chromium V8, Fortinet and Citrix NetScaler to its Known Exploited Vulnerabilities (KEV) catalog.

The entries are CVE-2025-25249 (Fortinet multiple products heap-based buffer overflow), CVE-2026-19490 (Citrix NetScaler authentication bypass via an alternate path or channel), CVE-2026-87491 (Google Chromium V8 out-of-bounds write), and CVE-2026-20079 (Cisco Firepower Management Center authentication bypass via an alternate path or channel). CISA notes these are actively exploited, with specific implications outlined for each product family.

Among the four, CVE-2026-20079 has a CVSS score of 10.0 and affects Cisco Secure FMC’s web interface, allowing unauthenticated remote attackers to bypass authentication by sending crafted HTTP requests and potentially obtaining root access to the underlying operating system. CVE-2026-87491, with a CVSS of 8.8, is described as the seventh actively exploited Chrome zero‑day of 2026, enabling arbitrary code execution through an out-of-bounds write in the V8 engine; Google fixed it in Chrome 153.0.8010.36 and later.

CVE-2025-25249, rated 8.1, is a heap overflow in Fortinet’s cw_acd daemon used to deliver remote code execution via specially crafted packets, with known in‑the‑wild abuse, including PivotC2 activity on compromised FortiGate devices. Finally, CVE-2026-19490, scoring 9.3, enables authentication bypass on Citrix NetScaler ADC and NetScaler Gateway via the SAML HTTP-Redirect binding, potentially granting access to protected services.

CISA emphasises compliance deadlines under BOD 22-01, urging federal agencies to fix the Windows-related item by 22 September 2026 and the remaining flaws by 12 September 2026, with private organisations advised to review the KEV catalog and address the vulnerabilities accordingly.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline