VMTech
Discuss a project

CISA Requires Federal Patches for Exploited Cisco, Citrix and Fortinet Flaws

CISA Requires Federal Patches for Exploited Cisco, Citrix and Fortinet Flaws

The U.S. Cybersecurity and Infrastructure Security Agency has added three vulnerabilities affecting Cisco, Citrix and Fortinet products to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies must remediate the issues by September 12, 2026.

The additions cover CVE-2026-20079 in Cisco Secure Firewall Management Center Software, CVE-2026-19490 in Citrix NetScaler ADC and NetScaler Gateway, and CVE-2025-25249 in Fortinet FortiOS, FortiSwitchManager and FortiSASE. All three are being exploited, making patching and exposure reduction an immediate operational priority.

Three perimeter vulnerabilities under active exploitation

CVE-2026-20079 has a CVSS score of 10.0. The authentication-bypass flaw in the Cisco Secure Firewall Management Center web interface can allow an unauthenticated remote attacker to bypass authentication, execute script files and obtain root access to the underlying operating system. Cisco said it became aware of active exploitation in August 2026, without publishing further details.

CVE-2026-19490, scored 9.3, is an authentication-bypass vulnerability affecting NetScaler ADC and NetScaler Gateway when configured as an AAA virtual server or Gateway, including SSL VPN, ICA Proxy, CVPN and RDP Proxy deployments. Previdian recorded 56 exploitation attempts against its honeypot systems from September 3, including 36 on September 8 alone.

The Fortinet issue, CVE-2025-25249, has a CVSS score of 7.3 and is a heap-based buffer overflow. A remote unauthenticated attacker could execute arbitrary code or commands through specially crafted requests against affected FortiOS, FortiSwitchManager and FortiSASE products.

Observed campaigns raise the stakes

SOCRadar linked exploitation of the Fortinet flaw to a campaign delivering the Node.js remote-access trojan PivotC2. The activity is estimated to have targeted more than 3,000 IP addresses and infected 178 devices, predominantly in the U.S. Researchers assess the financially motivated activity as the work of a Russian-speaking threat actor, with evidence of exploitation dating to July 2026.

In observed attacks, a shell script and exploit binary target a vulnerable FortiGate instance to establish a reverse shell. A one-line Node.js command then downloads, decrypts and executes a second-stage JavaScript payload. PivotC2 maintains a persistent outbound TLS connection and offers interactive shells, file transfers, proxy tunnelling, port forwarding, CIDR-range scanning, configuration harvesting and credential decryption.

The Cisco risk also fits a broader pattern of router-focused intrusion activity. In Cisco vulnerability chains and ClickFix activity, Cisco vulnerability chains and ClickFix activity illustrate why perimeter devices need prompt attention alongside endpoint controls. Sygnia recently described the China-nexus Fire Ant group obtaining access to Cisco IOS XR routers, using custom malware for persistence, data collection and deeper movement into high-value networks.

What security teams should do now

KEV inclusion establishes a federal remediation deadline, but the underlying exposure is relevant to every organisation operating these products. Edge appliances can have limited monitoring or telemetry, while attackers continuously scan them for an initial foothold.

Security teams should identify exposed Cisco, Citrix and Fortinet systems, apply vendor fixes, limit unnecessary internet access and hunt for indicators of compromise. For Fortinet deployments, SOCRadar also recommends credential rotation after suspected exposure. The practical business implication is clear: treating these appliances as monitored, patch-managed critical assets reduces the opportunity for an edge-device compromise to become a wider network intrusion.

#cybersecurity#vulnerability#networksecurity#patchmanagement
Open analytics
On the site 0 views
min read 4 10.09.2026
Instagram

CISA Requires Federal Patches for Exploited Cisco, Citrix and Fortinet Flaws

Open the post on Instagram ↗