The U.S. Cybersecurity and Infrastructure Security Agency has added three high-severity vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities catalog. All federal civilian agencies (FCEB) are being ordered to deploy patches by September 12, 2026 to mitigate active attacks exploiting these flaws.
The Three Flaws and Their Threats
First is CVE-2026-20079, a critical (CVSS 10.0) issue in Cisco’s Secure Firewall Management Center. It permits remote attackers with no authentication to bypass login and execute scripts on the device, allowing root-level control of the underlying system.
Next, CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway when configured as an AAA virtual server or acting as SSL VPN, ICA Proxy, CVPN, or RDP Proxy. This vulnerability (CVSS 9.3) also enables authentication bypass and remote access. Scans and exploit attempts have already been detected, including dozens against honeypots just this past week.
The third flaw is CVE-2025-25249, a heap-based buffer overflow in Fortinet software products including FortiOS, FortiSwitchManager, and FortiSASE (CVSS score 7.3). It allows unauthenticated remote attackers to execute code or commands through specially crafted requests. This vulnerability has been weaponized in a widespread campaign distributing a Node.js remote access trojan dubbed PivotC2.
Real-World Exploitation & Campaign Activity
Cisco reversed course and flagged active exploitation of their CVE-2026-20079 bug in August 2026. While details remain scarce, the urgency is clear: attackers are targeting this weakness in live environments.
Citrix’s bug, CVE-2026-19490, has seen documented attempts—56 in total since September 3—with 36 incidents logged just on September 8 in honeypot setups. That level of probing suggests probing for systems yet to be patched.
The Fortinet vulnerability has been leveraged by a Russian-speaking threat actor in a campaign infecting at least 178 devices. Tactics include using reverse shells, JavaScript payloads, and a persistent TLS channel, with features like tunneling, proxying, credential theft, scanning, and autonomous execution once compromised. Over 3,000 IP addresses were targeted, mostly within the United States.
CISA’s inclusion of these flaws in its KEV list forces federal agencies to comply under a strict patching deadline. The agency’s authority aims to ensure rapid mitigation of threats targeting federal infrastructure, but also has ripple effects for any organization using affected equipment.
What Organizations Should Do Now
Administrators using Cisco FMC, Citrix NetScaler ADC/Gateway, or any of the impacted Fortinet systems should prioritize patching without delay. Additional steps include tightening external access, rotating credentials, monitoring for indicators of compromise (IoCs), and reviewing logs and telemetry for signs of exploitation.
Maintaining strong perimeter defenses is crucial as attacks increasingly target network edge devices—routers, VPN gateways, firewalls—that are exposed to the internet but often lack deep visibility.
This directive underscores a broader trend: attackers are routinely scanning for and exploiting flaws in widely deployed network appliances. With federal deadlines now enforced, the pressure is on not just for U.S. agencies, but for any enterprise relying on these platforms to update and protect their infrastructure.