CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
CISA adds actively exploited Cisco, Citrix, and Fortinet edge-device flaws to KEV catalog, ordering federal agencies to patch by September 12, 2026.
CISA added CVE-2026-20079 (Cisco Secure Firewall Management Center authentication bypass, CVSS 10.0), CVE-2026-19490 (Citrix NetScaler ADC/Gateway authentication bypass, CVSS 9.3), and CVE-2025-25249 (FortiOS heap buffer overflow, CVSS 7.3) to the Known Exploited Vulnerabilities catalog with a September 12, 2026 deadline for FCEB agencies. Cisco confirmed active exploitation of CVE-2026-20079 in August 2026, while Previdian honeypots logged 56 NetScaler exploitation attempts since September 3. SOCRadar attributes Fortinet exploitation to a financially motivated Russian-speaking actor deploying the PivotC2 Node.js RAT, infecting 178 of over 3,000 targeted IP addresses, mostly in the US.
- CISA added three flaws to KEV with a September 12, 2026 federal patch deadline
- Cisco FMC CVE-2026-20079 (CVSS 10.0) allows unauthenticated root access; exploited in August 2026
- Citrix NetScaler bypass saw 56 honeypot exploitation attempts since September 3
- Fortinet CVE-2025-25249 used to deploy PivotC2 Node.js RAT on 178 devices, mostly US
- SOCRadar urges patching, IOC hunting, credential rotation, and limiting internet exposure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-25249 | Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known. Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product. | 9.8 | 2% | KEV PoC |
| mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants) | |
| CVE-2026-19490 | Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile). Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected. | 9.3 | 6% | KEV PoC |
| largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances | |
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) |
Full article634 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 10, 2026Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
The vulnerabilities are listed below -
- CVE-2026-20079 (CVSS score: 10.0) - An authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
- CVE-2026-19490 (CVSS score: 9.3) - An authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
- CVE-2025-25249 (CVSS score: 7.3) - A heap-based buffer overflow vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that could allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
The development comes as Cisco updated its advisory for CVE-2026-20079 to note that it became aware of active exploitation efforts targeting the flaw in August 2026. It did not disclose any additional details.
Cisco routers have been an attack magnet in recent years. In a report published late last month, Sygnia said it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.
"This behavior shifts the router's role from a transit device to a collection platform," the cybersecurity company noted. "Once the actor controlled the router, the device became a vantage point for observing traffic moving through trusted network paths."
CVE-2026-19490, on the other hand, has witnessed exploitation activity targeting Previdian's honeypot systems, with a total of 56 attempts registered since September 3, 2026. Of these, 36 attempts were recorded on September 8, 2026, alone.
The addition of CVE-2025-25249 to the KEV catalog follows a report from SOCRadar about a malicious attack campaign that's suspected to have weaponized the flaw to deliver a feature-rich Node.js remote access trojan (RAT) codenamed PivotC2. The post-exploitation framework supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.
More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2. The majority of the compromises are concentrated in the U.S. The activity is assessed to be the work of a Russian-speaking threat actor driven by financial gain. The earliest evidence of active exploitation of the flaw dates back to July 2026.
In the observed attacks, a shell script containing an exploit binary targets a vulnerable FortiGate instance to establish a reverse shell and run a single-line JavaScript command via Node.js. This, in turn, leads to the download of a second-stage JavaScript payload, which is decrypted and executed to deliver PivotC2.
"PivotC2 establishes a persistent outbound TLS connection to a remote command-and-control (C2) server. Its feature set includes interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, local and remote port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption," SOCRadar said. "An auto-mode flag enables autonomous operations, automatically running a predefined command sequence upon initial infection."
The findings once again demonstrate that threat actors are continuously scanning exposed perimeter edge devices to obtain initial access by taking advantage of their lack of robust monitoring or telemetry logging. SOCRadar is recommending organizations using Fortinet products to limit internet access, hunt for indicators of compromise, rotate credentials, and apply the latest patches.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html