CISA Mandates Patching for Critical Cisco, Citrix, and Fortinet Vulnerabilities
Share
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three critical vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalogue. Federal Civilian Executive Branch (FCEB) agencies are required to apply necessary security patches by 12 September 2026.
Critical Flaws in Cisco and Citrix Systems
The most severe vulnerability, identified as CVE-2026-20079, carries a CVSS score of 10.0. This authentication bypass flaw affects the web interface of Cisco Secure Firewall Management Center (FMC) software. An unauthenticated remote attacker can exploit the vulnerability to execute script files and obtain root access to the device’s underlying operating system. Cisco confirmed that active exploitation of this flaw was detected in August 2026.
The vulnerability comes amid broader targeting of Cisco infrastructure. Cybersecurity firm Sygnia recently observed a China-linked espionage group, dubbed Fire Ant, abusing Cisco IOS XR routers to facilitate data collection and network persistence.
Citrix is also impacted by CVE-2026-19490, which holds a CVSS score of 9.3. This vulnerability allows for authentication bypass in NetScaler ADC and NetScaler Gateway appliances when configured as an AAA virtual server or as a Gateway, including SSL VPN and RDP Proxy services. Monitoring of honeypot systems has already recorded significant exploitation activity, including a surge of attempts on 8 September 2026.
Fortinet Vulnerability Linked to PivotC2 Malware
The third entry, CVE-2025-25249, involves a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE. This flaw, which has a CVSS score of 7.3, enables unauthenticated remote attackers to execute arbitrary code through specifically crafted requests.
Security researchers at SOCRadar have linked the exploitation of this Fortinet flaw to a campaign delivering a Node.js remote access trojan (RAT) known as PivotC2. The malware is designed to support interactive shells, network scanning, and the harvesting of configurations and credentials. The campaign, suspected to be the work of Russian-speaking actors seeking financial gain, has targeted more than 3,000 IP addresses and resulted in the infection of at least 178 devices, many of which are located in the United States.
To mitigate these risks, organisations using Fortinet products are advised to limit internet-facing access, rotate credentials, and perform hunts for indicators of compromise while applying the latest patches.




Leave a Reply