CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, imposing a mandatory remediation deadline of September 12, 2026, for federal civilian executive branch agencies. The flagged defects include a critical authentication bypass in Cisco Secure Firewall Management Center (CVE-2026-20079), an authentication bypass in Citrix NetScaler ADC (CVE-2026-19490), and a heap-based buffer overflow in Fortinet FortiOS (CVE-2025-25249). These additions follow recent reports of active exploitation, including state-sponsored espionage against Cisco routers and a Russian-linked campaign using the Fortinet flaw to deploy the PivotC2 remote access trojan.