CISA Adds Actively Exploited Cisco, Chrome V8, Fortinet, and Citrix NetScaler Flaws to KEV as Unverified Underground FortiGate Exploit Sale Emerges
CISA added four exploited vulnerabilities to its KEV catalog — Cisco Secure FMC CVE-2026-20079 (CVSS 10.0), Chrome V8 CVE-2026-87491 (CVSS 8.8), Fortinet CVE-2025-25249 (CVSS 8.1), and Citrix NetScaler CVE-2026-19490 (CVSS 9.3) — with a September 12, 2026…
Reported on September 10, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to patch by September 12, 2026. The additions are: CVE-2026-20079 (CVSS 10.0), an unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access; CVE-2026-87491 (CVSS 8.8), an out-of-bounds write in Chrome's V8 engine — the seventh actively exploited Chrome zero-day of 2026 — fixed in Chrome 153.0.8010.36; CVE-2025-25249 (CVSS 8.1), a heap-based buffer overflow in the cw_acd daemon of FortiOS/FortiSwitchManager being exploited with the PivotC2 RAT against FortiGate devices; and CVE-2026-19490 (CVSS 9.3), a CWE-288 SAML HTTP-Redirect binding authentication bypass in Citrix NetScaler ADC and Gateway when configured as AAA virtual servers or Gateway services (including SSL VPN, ICA Proxy, and RDP Proxy). Citrix released fixes on August 19, 2026 in builds 14.1-73.32 and 13.1-63.21; builds 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21 are affected, and newer installations require exposed SAML IdP configuration. Honeypots recorded 56 attack attempts against the NetScaler flaw between September 3 and 8 after a public PoC appeared; the sources differ on exploitation status — honeypot data shows no confirmed production compromises, while CISA's KEV listing reflects active exploitation, and the KEV deadline includes mandatory forensic triage. Separately, Dark Web Intelligence flagged an unverified underground sale of a claimed private '1-day' FortiGate SSL VPN remote code execution exploit for FortiOS 7.2.x and 7.4.x, with a claimed proof-of-concept video but no CVE, affected builds, or technical details — it could be a new flaw, a patched bug, or fraud. The listing coincides with confirmed in-the-wild exploitation of CVE-2025-25249, patched January 2026 but exploited since July 2026, and CVE-2024-21762, a critical out-of-bounds write in the FortiOS and FortiProxy SSL VPN component that continues to be abused against exposed FortiGate systems. Fortinet has advised disabling SSL VPN where immediate upgrades are not possible.
- CISA added four actively exploited vulnerabilities to its KEV catalog (reported September 10, 2026); federal civilian agencies must patch by September 12, 2026, with mandatory forensic triage for the NetScaler entry.
- CVE-2026-20079 (CVSS 10.0): unauthenticated authentication bypass in Cisco Secure Firewall Management Center's web interface enabling script execution and potential root access.
- CVE-2026-87491 (CVSS 8.8): out-of-bounds write in Chrome's V8 engine, the seventh actively exploited Chrome zero-day of 2026, fixed in Chrome 153.0.8010.36.
- CVE-2025-25249 (CVSS 8.1): heap-based buffer overflow in the cw_acd daemon of FortiOS/FortiSwitchManager, exploited with the PivotC2 RAT; patched January 2026 but exploited in real attacks since July 2026.
- CVE-2026-19490 (CVSS 9.3, CWE-288): NetScaler SAML HTTP-Redirect binding authentication bypass affecting AAA virtual servers and Gateway configurations (SSL VPN, ICA Proxy, RDP Proxy).
- NetScaler fixes ship in builds 14.1-73.32 and 13.1-63.21 (released August 19, 2026); builds 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21 are affected, and newer installations require exposed SAML IdP configuration.
- Honeypots recorded 56 attack attempts against the NetScaler flaw between September 3 and 8, 2026, after a public PoC appeared; sources differ — no confirmed production compromises reported, though CISA's KEV listing reflects active…
- An unverified underground listing offers a claimed private '1-day' FortiGate SSL VPN RCE exploit for FortiOS 7.2.x/7.4.x with a claimed PoC video but no CVE, affected builds, or technical details; it could be a new flaw, a patched bug, or…
Coverage timelineoldest first · each row is one article
- · 7d agoCISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
Cyber Security News· 76
CISA adds exploited Citrix NetScaler authentication bypass CVE-2026-19490 to the KEV catalog; federal agencies must patch by September 12.
- · 6d agoU.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Security Affairs· 84
CISA added actively exploited Cisco FMC, Chrome V8, Fortinet and Citrix NetScaler flaws to its KEV catalog, ordering federal patching by September 12.
- · 3h agoHackers Allegedly Selling Fortinet FortiGate 1-Day Vulnerability on Underground Forums
Cyber Security News· 64
An unverified underground listing offers a claimed FortiGate SSL VPN RCE exploit for FortiOS 7.2.x/7.4.x amid ongoing exploitation of known Fortinet flaws.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) | |
| CVE-2025-25249 | Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known. Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product. | 9.8 | 2% | KEV PoC |
| mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants) | |
| CVE-2026-19490 | Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile). Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected. | 9.3 | 6% | KEV PoC |
| largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances | |
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-87491 | Actively Exploited Out-of-Bounds Write in Google Chrome V8 CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown. Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching. | 8.8 | <1% | KEV |
| massbillions of installations (Chrome's install base exceeds 3 billion users) |