CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
- ID
- 23165
- Status
- summarized
- Published
- 10 Sep 2026, 6:36 PM
- Fetched
- 10 Sep 2026, 9:12 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 10 Sep 2026, 9:15 PM
- Tags
- Audience
- developerssaas_founders
What happened
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-20079 (CVSS 10.0, Cisco Secure Firewall FMC authentication bypass granting root), CVE-2026-19490 (CVSS 9.3, Citrix NetScaler ADC/Gateway auth bypass), and CVE-2025-25249 (CVSS 7.3, Fortinet FortiOS/FortiSwitchManager/FortiSASE heap overflow). Federal agencies must patch by September 12, 2026. The Cisco flaw has been exploited since August 2026; the Citrix flaw saw 56 honeypot exploitation attempts since September 3, with 36 on September 8 alone.
Why it matters
If your org or cloud provider runs Cisco FMC, Citrix NetScaler ADC/Gateway as an AAA or SSL VPN virtual server, or Fortinet FortiOS/FortiSASE, patch immediately—these are under active exploitation with root-level or RCE impact. For everyone else, no action needed unless you manage these specific network appliances.
Discussion angle
Quick check: does anyone on the call know if their hosting provider or office network runs Cisco FMC, NetScaler, or FortiOS? If yes, this is a today problem; if no, move on.