ZeroHour
Story · 4 sources · 6 articlesfirst updated ()

CISA Adds Exploited Cisco, Citrix NetScaler, Chrome V8, and Fortinet Flaws to KEV Catalog with Sept. 12 Federal Patch Deadline

What's new: The story expands beyond the previously covered Fortinet flaw: CISA's September 9, 2026 KEV update also added Cisco Secure Firewall Management Center CVE-2026-20079 (CVSS 10.0, exploited in August 2026), Citrix NetScaler CVE-2026-19490 (CVSS 9.3, patched August 19 in 14.1-73.32/13.1-63.21, with 56 honeypot exploitation attempts logged September 3-8 after a public GitHub exploit and no confirmed…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CISA added four actively exploited vulnerabilities to its KEV catalog on September 9, 2026 — Cisco Secure Firewall Management Center CVE-2026-20079 (CVSS 10.0), Citrix NetScaler CVE-2026-19490 (CVSS 9.3), Chrome V8 CVE-2026-87491 (CVSS 8.8), and Fortinet…

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 9, 2026, giving federal civilian agencies until September 12, 2026 to remediate under Binding Operational Directive 26-04, with mandatory forensic triage of affected environments rather than routine patching alone. The additions are CVE-2026-20079, a CVSS 10.0 unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access, which Cisco confirmed was actively exploited in August 2026; CVE-2026-87491, a CVSS 8.8 out-of-bounds write in Chrome's V8 engine fixed in Chrome 153.0.8010.36 and the seventh actively exploited Chrome zero-day of 2026; CVE-2026-19490, a CVSS 9.3 CWE-288 authentication bypass (described by Security Affairs as a SAML HTTP-Redirect binding bypass) affecting NetScaler ADC and Gateway appliances configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA virtual servers; and CVE-2025-25249, a heap-based buffer overflow (CWE-122/CWE-787) in FortiOS and FortiSwitchManager's cw_acd daemon allowing unauthenticated remote code execution via specially crafted packets. Sources disagree on the Fortinet CVSS score: SecurityWeek lists 7.4, The Hacker News 7.3, and Security Affairs 8.1. Citrix patched CVE-2026-19490 on August 19, 2026 in builds 14.1-73.32 and 13.1-63.21, and Rapid7 said it is remotely exploitable without authentication; Previdian honeypots logged 56 exploitation attempts between September 3 and 8, beginning one day after a public exploit appeared on GitHub, with no confirmed production compromises reported. SOCRadar attributes the Fortinet attacks to a likely Russian-speaking, financially motivated cybercrime actor deploying the AI-assisted PivotC2 Node.js RAT since July 2026: more than 30,000 IP addresses were scanned (The Hacker News reports over 3,000 targeted — sources disagree), 178 devices were infected, and at least two US intrusions with data exfiltration were confirmed. The Fortinet flaw was patched in January, with fixes in FortiOS 7.6.4, 7.4.9, 7.2.12, and 7.0.18 and FortiSwitchManager 7.2.7 and 7.0.6. CISA lists ransomware use of CVE-2025-25249 as unknown and warns that internet-facing FortiOS, FortiSwitchManager, and FortiSASE assets are a likely foothold for credential theft, persistence, and lateral movement.

  • CISA added four actively exploited vulnerabilities to the KEV catalog on September 9, 2026; FCEB agencies must patch by September 12, 2026 under BOD 26-04, with mandatory forensic triage.
  • CVE-2026-20079 (CVSS 10.0): unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access; Cisco confirmed active exploitation in August 2026.
  • CVE-2026-87491 (CVSS 8.8): out-of-bounds write in Chrome's V8 engine, fixed in Chrome 153.0.8010.36; the seventh actively exploited Chrome zero-day of 2026.
  • CVE-2026-19490 (CVSS 9.3, CWE-288): authentication bypass in NetScaler ADC and Gateway configured as SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA virtual servers; Security Affairs describes it as a SAML HTTP-Redirect binding bypass; newer…
  • Citrix patched CVE-2026-19490 on August 19, 2026; fixes in 14.1-73.32 and 13.1-63.21 (affected builds: 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21); Rapid7 said it is remotely exploitable without authentication.
  • Previdian honeypots logged 56 NetScaler exploitation attempts between September 3 and 8, starting one day after a public exploit appeared on GitHub, with matching requests from three IPs across three countries; no confirmed production…
  • CVE-2025-25249: heap-based buffer overflow (CWE-122/CWE-787) in FortiOS/FortiSwitchManager's cw_acd daemon allowing unauthenticated RCE via crafted packets; Cyber Security News also lists FortiSASE as affected; sources disagree on CVSS…
  • SOCRadar: attackers scanned 30,000+ IP addresses (The Hacker News reports over 3,000 targeted — sources disagree), infected 178 devices with the PivotC2 Node.js RAT, and confirmed at least two US intrusions with data exfiltration.

Coverage timeline

  1. · 6d ago
    SecurityWeek· 82
    Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

    Threat actors exploit Fortinet heap-based buffer overflow CVE-2025-25249 to deploy PivotC2 RAT, infecting 178 devices and exfiltrating data from US targets.

  2. · 6d ago
    The Hacker News· 85
    CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    CISA adds actively exploited Cisco, Citrix, and Fortinet edge-device flaws to KEV catalog, ordering federal agencies to patch by September 12, 2026.

  3. · 6d ago
    Cyber Security News· 85
    CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks

    CISA added actively exploited Fortinet CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to its KEV catalog.

  4. · 6d ago
    SecurityWeek· 90
    Critical NetScaler Vulnerability Exploited in Attacks

    CISA added critical Citrix NetScaler flaw CVE-2026-19490 (CVSS 9.3) to its KEV catalog after confirming exploitation of gateway and AAA virtual servers in the wild.

  5. · 6d ago
    Cyber Security News· 76
    CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks

    CISA adds exploited Citrix NetScaler authentication bypass CVE-2026-19490 to the KEV catalog; federal agencies must patch by September 12.

  6. · 6d ago
    Security Affairs· 84
    U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

    CISA added actively exploited Cisco FMC, Chrome V8, Fortinet and Citrix NetScaler flaws to its KEV catalog, ordering federal patching by September 12.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
CVE-2026-19490
Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile).

Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected.

9.36% KEV PoC
  • Citrix NetScaler ADC and NetScaler Gateway
largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-87491
Actively Exploited Out-of-Bounds Write in Google Chrome V8

CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching.

8.8<1% KEV
  • Google Chrome (V8 JavaScript engine; tracked by CISA as 'Google Chromium V8') prior to 153.0.8010.36
massbillions of installations (Chrome's install base exceeds 3 billion users)