Site icon VMVirtualMachine.com

Resecurity | CISA KEV Alert: Cisco, Citrix, and Fortinet Vulnerabilities Under Active Exploitation

Resecurity | CISA KEV Alert: Cisco, Citrix, and Fortinet Vulnerabilities Under Active Exploitation

By resecurity.com
Publication Date: 2026-09-11 00:00:00

Executive Summary

On 9 September 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three high-impact vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, with Federal Civilian Executive Branch (FCEB) agencies required to remediate the vulnerabilities by 12 September 2026.

The three vulnerabilities affect security and remote-access infrastructure commonly deployed at the network perimeter:

  • CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC): An unauthenticated authentication-bypass vulnerability that can result in root access to the underlying FMC appliance.
  • CVE-2026-19490 — Citrix NetScaler ADC/Gateway: An authentication-bypass vulnerability affecting Gateway and AAA virtual-server configurations under specific conditions.
  • CVE-2025-25249 — Fortinet FortiOS: A pre-authentication heap-based buffer overflow in the cw_acd daemon that can result in remote code or command execution.

Cisco has…

Exit mobile version