Download Privacy Needle App

Type to search

Cybersecurity

CISA Mandates Patching for Critical Cisco, Citrix, and Fortinet Vulnerabilities

Share

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three critical vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalogue. Federal Civilian Executive Branch (FCEB) agencies are required to apply necessary security patches by 12 September 2026.

Critical Flaws in Cisco and Citrix Systems

The most severe vulnerability, identified as CVE-2026-20079, carries a CVSS score of 10.0. This authentication bypass flaw affects the web interface of Cisco Secure Firewall Management Center (FMC) software. An unauthenticated remote attacker can exploit the vulnerability to execute script files and obtain root access to the device’s underlying operating system. Cisco confirmed that active exploitation of this flaw was detected in August 2026.

The vulnerability comes amid broader targeting of Cisco infrastructure. Cybersecurity firm Sygnia recently observed a China-linked espionage group, dubbed Fire Ant, abusing Cisco IOS XR routers to facilitate data collection and network persistence.

Citrix is also impacted by CVE-2026-19490, which holds a CVSS score of 9.3. This vulnerability allows for authentication bypass in NetScaler ADC and NetScaler Gateway appliances when configured as an AAA virtual server or as a Gateway, including SSL VPN and RDP Proxy services. Monitoring of honeypot systems has already recorded significant exploitation activity, including a surge of attempts on 8 September 2026.

Fortinet Vulnerability Linked to PivotC2 Malware

The third entry, CVE-2025-25249, involves a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE. This flaw, which has a CVSS score of 7.3, enables unauthenticated remote attackers to execute arbitrary code through specifically crafted requests.

Security researchers at SOCRadar have linked the exploitation of this Fortinet flaw to a campaign delivering a Node.js remote access trojan (RAT) known as PivotC2. The malware is designed to support interactive shells, network scanning, and the harvesting of configurations and credentials. The campaign, suspected to be the work of Russian-speaking actors seeking financial gain, has targeted more than 3,000 IP addresses and resulted in the infection of at least 178 devices, many of which are located in the United States.

To mitigate these risks, organisations using Fortinet products are advised to limit internet-facing access, rotate credentials, and perform hunts for indicators of compromise while applying the latest patches.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.