ZeroHour
Story · 1 source · 1 articlefirst updated ()

CISA KEV Batch Adds Exploited NetScaler, Cisco, Chrome, and Fortinet Flaws; Underground '1-Day' FortiGate Exploit Listing Surfaces

What's new: New since the previous summary: an underground forum advertisement (shared by Dark Web Intelligence) offers a claimed FortiGate SSL VPN '1-day' RCE exploit for FortiOS 7.2.x/7.4.x with a purported PoC video but no CVE, firmware builds, or technical details — unverified and possibly fraudulent. It arrives amid confirmed in-the-wild exploitation of CVE-2025-25249 (patched January 2026, exploited…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CISA added four actively exploited vulnerabilities to its KEV catalog — Citrix NetScaler auth bypass CVE-2026-19490 (CVSS 9.3), Cisco Secure FMC auth bypass CVE-2026-20079 (CVSS 10.0), Chrome V8 zero-day CVE-2026-87491 (CVSS 8.8), and Fortinet CVE-2025-25249…

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to patch by September 12, 2026 under BOD 26-04's three-day deadline, with mandatory forensic triage. The flagship addition is CVE-2026-19490 (CVSS 9.3, CWE-288), an authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; Security Affairs describes it as a SAML HTTP-Redirect binding authentication bypass, and Cyber Security News notes newer installations require an exposed SAML IdP configuration. Rapid7 assesses the bug as remotely exploitable without authentication. Citrix released fixes on August 19, 2026, shipping in builds 14.1-73.32 and 13.1-63.21 (affected: 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21). A public exploit/PoC appeared on GitHub, and Previdian sensor data shows exploitation ongoing since at least September 3 — one day after the exploit posted — with matching requests from three IPs across three countries; honeypots recorded 56 attack attempts between September 3 and 8, though no confirmed production compromises have been reported. The same KEV update also included: CVE-2026-20079 (CVSS 10.0), an unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access; CVE-2026-87491 (CVSS 8.8), an out-of-bounds write in Chrome's V8 engine — the seventh actively exploited Chrome zero-day of 2026 — fixed in Chrome 153.0.8010.36; and CVE-2025-25249 (CVSS 8.1), a heap-based buffer overflow in FortiOS/FortiSwitchManager's cw_acd daemon exploited with the PivotC2 RAT. In a related development, Dark Web Intelligence shared an underground forum advertisement for a private '1-day' remote code execution exploit targeting FortiGate SSL VPN appliances on FortiOS 7.2.x and 7.4.x, with a claimed proof-of-concept video but no CVE, affected builds, or technical details — it could be a new flaw, a patched bug, or fraud. The listing coincides with confirmed in-the-wild exploitation of CVE-2025-25249, patched in January 2026 but exploited in real attacks since July 2026, and CVE-2024-21762, a critical out-of-bounds write in the FortiOS and FortiProxy SSL VPN component; Fortinet advises disabling SSL VPN where immediate upgrades are not possible.

  • CISA added four actively exploited vulnerabilities to its KEV catalog; federal civilian agencies must patch by September 12, 2026 under BOD 26-04 (three-day deadline) with mandatory forensic triage.
  • CVE-2026-19490 (CVSS 9.3, CWE-288): authentication bypass in Citrix NetScaler ADC/Gateway configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; Security Affairs describes it as a SAML HTTP-Redirect binding…
  • Citrix patched CVE-2026-19490 on August 19, 2026; fixes ship in 14.1-73.32 and 13.1-63.21 (affected: 14.1 before 14.1-73.32, 13.1 before 13.1-63.21); Rapid7 says it is remotely exploitable without authentication.
  • A public exploit/PoC appeared on GitHub; exploitation observed since at least September 3 (Previdian: matching requests from three IPs across three countries); honeypots logged 56 attack attempts September 3-8; no confirmed production…
  • CVE-2026-20079 (CVSS 10.0): unauthenticated Cisco Secure Firewall Management Center web-interface auth bypass enabling script execution and potential root access.
  • CVE-2026-87491 (CVSS 8.8): out-of-bounds write in Chrome's V8 engine — the seventh actively exploited Chrome zero-day of 2026 — fixed in Chrome 153.0.8010.36.
  • CVE-2025-25249 (CVSS 8.1): heap-based buffer overflow in FortiOS/FortiSwitchManager's cw_acd daemon, exploited with the PivotC2 RAT; patched January 2026 but exploited in real attacks since July 2026.
  • An unverified underground listing offers a private '1-day' FortiGate SSL VPN RCE exploit for FortiOS 7.2.x/7.4.x with a claimed PoC video; no CVE, builds, or technical details provided — could be a new flaw, a patched bug, or fraud.

Coverage timeline

  1. · 7d ago
    SecurityWeek· 90
    Critical NetScaler Vulnerability Exploited in Attacks

    CISA added critical Citrix NetScaler flaw CVE-2026-19490 (CVSS 9.3) to its KEV catalog after confirming exploitation of gateway and AAA virtual servers in the wild.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21762
Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy

CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted.

Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority.

9.884% KEV ransomware
  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7
mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans)
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
CVE-2026-19490
Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile).

Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected.

9.36% KEV PoC
  • Citrix NetScaler ADC and NetScaler Gateway
largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-87491
Actively Exploited Out-of-Bounds Write in Google Chrome V8

CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching.

8.8<1% KEV
  • Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36
massbillions of installations (Chrome's install base exceeds 3 billion users)