CISA Flags Three Critical Flaws in Cisco, Citrix, and Fortinet Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch them by September 12, 2026.
The flaws affect Cisco's Secure Firewall Management Center Software, Citrix NetScaler ADC and Gateway, and Fortinet's FortiOS, FortiSwitchManager, and FortiSASE. CVE-2026-20079 has a CVSS score of 10.0, allowing an attacker to bypass authentication and execute script files on the affected device.
Cisco routers have been targeted by cyber espionage groups, including Fire Ant, which exploited routers to facilitate persistence, data collection, and malware deployment. Meanwhile, CVE-2026-19490 has seen exploitation activity targeting Citrix NetScaler ADC and Gateway appliances, with 56 attempts recorded since September 3.
The addition of CVE-2025-25249 follows a report from SOCRadar about a malicious attack campaign that used the flaw to deliver a Node.js remote access trojan (RAT) codenamed PivotC2. The campaign targeted over 3,000 IP addresses and infected around 178 devices.