Actively exploited Cisco FMC and Chrome zero-days hit CISA's KEV catalog as BlueMoon kit, Cyclops Blink and Qilin ransomware campaigns unfold
CISA added four actively exploited flaws — Cisco FMC CVE-2026-20079 (CVSS 10.0), Chrome V8 CVE-2026-87491 (CVSS 8.8), Fortinet CVE-2025-25249 and Citrix NetScaler CVE-2026-19490 — to its KEV catalog with a September 12, 2026 federal patch deadline. Proofpoint…
Reported September 10, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, giving US federal civilian (FCEB) agencies until September 12, 2026 to patch: CVE-2026-20079 (CVSS 10.0), an unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access; CVE-2026-87491 (CVSS 8.8), a Chrome V8 flaw listed as fixed in Chrome 153.0.8010.36 and counted as the seventh actively exploited Chrome zero-day of 2026; CVE-2025-25249 (CVSS 8.1), a heap-based buffer overflow in the FortiOS/FortiSwitchManager cw_acd daemon being exploited with the PivotC2 RAT on FortiGate devices; and CVE-2026-19490 (CVSS 9.3), a Citrix NetScaler SAML HTTP-Redirect binding authentication bypass. A second FMC flaw, CVE-2026-20316 (CVSS 5.3), which allows login via a low-privileged static account exposing sensitive data, had already been added to KEV in late July 2026. The Chrome flaw sits in the middle of a three-part chain — CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (described as a V8/WebAssembly sandbox escape by Proofpoint and Volexity, though CISA's KEV listing calls it an out-of-bounds write) and CVE-2026-85880 (Windows kernel/ALPC privilege escalation in RtlpCreateServerAcl) — that Proofpoint, working with Google Threat Intelligence Group, Microsoft Threat Intelligence Center and Volexity, tracks as the BlueMoon exploit kit. China-linked Violet Typhoon (APT31) first used BlueMoon on August 28, 2026 against US NGOs and mining and commodity trading firms via rapport-building spear phishing with internship and conference lures; UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket adopted it within days against aerospace, manufacturing, government and finance targets in the US, Vietnam, Indonesia and Singapore. The kit exploited a patch gap: fixes for the V8 flaws had landed in upstream Chromium source but had not yet reached Chrome stable releases; all three CVEs were patched between September 3 and September 2026 Patch Tuesday. The kit fingerprints the host and injects a CreateProcess stub into the Chrome broker process to download and execute a payload via curl; Proofpoint notes adoption was fast but noisy, that financially motivated adoption is expected, and that development artifacts suggest AI may have been used to build the kit. Separately, Volexity documented campaigns detected September 1, 2026 in which UTA0560 and JungleBamboo…
- CISA added four actively exploited vulnerabilities to its KEV catalog (reported September 10, 2026) with a September 12, 2026 patch deadline for US federal civilian (FCEB) agencies.
- CVE-2026-20079 (CVSS 10.0): unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and root-level code execution.
- CVE-2026-20316 (CVSS 5.3): permits FMC login via a low-privileged static account exposing sensitive data; can be chained for privilege escalation; added to KEV in late July 2026.
- CVE-2026-87491 (CVSS 8.8): Chrome V8 flaw — CISA's KEV listing describes an out-of-bounds write fixed in Chrome 153.0.8010.36, while Proofpoint and Volexity describe it as a V8/WebAssembly sandbox escape; it is the seventh actively…
- CVE-2025-25249 (CVSS 8.1): heap-based buffer overflow in the FortiOS/FortiSwitchManager cw_acd daemon, exploited alongside the PivotC2 RAT on FortiGate devices.
- CVE-2026-19490 (CVSS 9.3): Citrix NetScaler SAML HTTP-Redirect binding authentication bypass.
- Proofpoint (with Google Threat Intelligence Group, Microsoft Threat Intelligence Center and Volexity) tracks a new exploit kit, BlueMoon, chaining CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (V8 sandbox escape) and CVE-2026-85880…
- China-linked Violet Typhoon (APT31) first used BlueMoon on August 28, 2026 against US NGOs and mining and commodity trading firms via rapport-building spear phishing with internship and conference lures.
Coverage timelineoldest first · each row is one article
- · 6d agoU.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Security Affairs· 84
CISA added actively exploited Cisco FMC, Chrome V8, Fortinet and Citrix NetScaler flaws to its KEV catalog, ordering federal patching by September 12.
- · 6d agoAttackers are weaponizing the gap between Chromium fixes and Chrome patches
CSO Online· 82
Espionage actors use the BlueMoon exploit kit to chain Chrome V8 and Windows kernel zero-days via spear phishing, gaining full admin on unpatched endpoints.
- · 6d agoCritical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers· 87
Threat actors actively exploit Cisco FMC CVE-2026-20079 (CVSS 10.0) for root access, with clusters linked to Sandworm and Qilin ransomware.
- · 6d agoCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
The Hacker News· 84
Three threat clusters including a Sandworm-linked group and Qilin ransomware operators exploit Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316.
- · 6d agoAttackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Security Affairs· 90
Three threat groups, including Qilin ransomware operators, exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 for root access, credential theft, and ransomware.
- · 5d agoChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers· 85
Volexity reports China-linked UTA0560 and JungleBamboo chained Chrome zero-day CVE-2026-85046 with kernel flaws to spy on NGOs.
- · 5d agoBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
SecurityWeek· 88
Proofpoint reports multiple espionage groups rapidly adopting BlueMoon, a new exploit kit chaining Chrome and Windows zero-days.
- · 3d agoSandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
GBHackers· 78
Sophos uncovers a 64-bit Cyclops Blink variant on hacked Cisco FMC appliances, adding internal network scanning and selective packet capture; linked to Sandworm.
- · 2d agoChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
The Hacker News· 85
Volexity attributes spear-phishing campaign exploiting Chrome-Windows zero-day chain to Chinese actors UTA0560 and APT31 deploying GRIMWEDGE and LONGTALE.
- · 2d agoOne Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Security Affairs· 85
Two China-linked APT groups reused identical Chrome/Windows zero-day chain against NGOs, deploying GRIMWIDGE backdoor and LONGTALE credential-stealing extension.
- · 7h agoHackers Allegedly Selling Fortinet FortiGate 1-Day Vulnerability on Underground Forums
Cyber Security News· 64
An unverified underground listing offers a claimed FortiGate SSL VPN RCE exploit for FortiOS 7.2.x/7.4.x amid ongoing exploitation of known Fortinet flaws.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) | |
| CVE-2025-25249 | Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known. Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product. | 9.8 | 2% | KEV PoC |
| mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants) | |
| CVE-2026-19490 | Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile). Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected. | 9.3 | 6% | KEV PoC |
| largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances | |
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20316 | Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile). Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29. | 5.3 | 11% | KEV ransomware |
| largeplausibly tens of thousands of FMC deployments worldwide (no published install base) | |
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… | |
| CVE-2026-85880 | Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain. Do: Apply Microsoft's September 2026 security (cumulative) updates for each affected Windows 10 and Windows Server build, as no public PoC or workaround is documented; CISA's KEV listing (added 2026-09-08) triggers BOD 26-04 patching requirements for federal agencies, so prioritize accordingly. Give priority to hosts where unprivileged users can log in — RDS/VDI servers, jump boxes, shared workstations — and to internet-exposed Windows servers, since an ALPC local privilege escalation is a common component in exploit chains combining remote code execution or browser flaws with elevation to SYSTEM. Organizations unable to patch promptly should follow BOD 26-04 guidance for cloud services or restrict local access to affected hosts until updates are applied. | 7.8 | <1% | KEV |
| mass≈100M+ Windows installations (Windows 10 1607–22H2 on consumer/enterprise endpoints plus widely deployed Windows Server 2012–2022) | |
| CVE-2026-87491 | Actively Exploited Out-of-Bounds Write in Google Chrome V8 CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown. Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching. | 8.8 | <1% | KEV |
| massbillions of installations (Chrome's install base exceeds 3 billion users) |