CISA Adds Four New Vulnerabilities to Its Known Exploited Vulnerabilities Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected assets include Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler.
CVE-2026-20079 is a high-severity authentication bypass issue affecting Cisco Secure FMC's web interface. An attacker can bypass authentication and send crafted HTTP requests to execute scripts, potentially gaining root access to the underlying operating system.
Another vulnerability, CVE-2026-87491, affects Google Chromium V8 and has been actively exploited in the wild. An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome's sandbox.
The CISA has ordered federal agencies to address these vulnerabilities by specific due dates, ranging from September 12th to September 22nd, 2026, to protect their networks against attacks exploiting the flaws in the catalog.