Three Exploited Edge Flaws Test CISA's Three-Day Patch Deadline
Security / analysis
Three Exploited Edge Flaws Test CISA's Three-Day Patch Deadline
Citrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.
Between Sept. 27 and Oct. 1, 2026, CISA added a Citrix NetScaler pair, a Cisco SD-WAN Manager flaw and a Fortinet FortiMail flaw to its Known Exploited Vulnerabilities (KEV) catalog. All are reachable from the network without credentials, and the federal deadlines reported for each work out to three days from listing. That is the speed Binding Operational Directive 26-04 reserves for its highest-risk tier, and the same directive tells agencies to preserve evidence before they patch.
The claim here is narrow. The directive's rules are written for flaws like these, and the three listings expose a tension inside it: a three-day clock and a forensic-first instruction pull in opposite directions on an appliance that may already be compromised.
What BOD 26-04 requires
CISA issued the directive on June 10, 2026 and updated it on Aug. 25. It sets three remediation deadlines for federal civilian agencies:
- 3 days for vulnerabilities on publicly exposed assets where the technical impact is total and exploitation is automatable.
- 14 days for exposed assets with partial impact or non-automatable exploitation.
- 60 days for internal assets, regardless of impact or automatability.
"Publicly exposed" means reachable by unauthenticated or untrusted parties over public networks. "Total" impact means the attacker can install arbitrary software or gain full privileges, and "automatable" means functional proof-of-concept code exists that achieves remote code execution. Per the Cloud Security Alliance's research note, the directive revokes BOD 19-02 and BOD 22-01 and drops CVSS severity scores as the sorting key.
- Exposed, total impact, automatable3 days
- Exposed, other KEV listings14 days
- Internal assets60 days
Source: CISA BOD 26-04 implementation guidance, accessed 2026-10-02
The three listings
CISA's own alert pages, as fetched, do not print a due date. The dates below come from the outlets named in the table, so treat them as reported rather than confirmed by CISA.
| Product | CVE | KEV listing | Reported due date |
|---|---|---|---|
| Citrix NetScaler ADC and Gateway | CVE-2026-88771, CVE-2026-88772 | Sept. 27 | Sept. 30 (Help Net Security) |
| Cisco Catalyst SD-WAN Manager | CVE-2026-76504 | Sept. 30 | Oct. 3 (Rapid7) |
| Fortinet FortiMail | CVE-2026-104286 | Oct. 1 | Oct. 4 (Suped) |
We covered each flaw in detail: the Citrix NetScaler zero-days, the Cisco SD-WAN Manager bypass and the FortiMail path traversal. Citrix's bulletin says exploitation of the first two NetScaler flaws "has been observed," Cisco's PSIRT said it became aware of exploitation in September, and Fortinet's advisory says exploitation is in the wild.
Neither CISA's pages nor the vendors' advisories name which BOD tier each listing falls in, so the three-day match is inferred from the dates and is not confirmed by CISA.
The Citrix row shows how thin the margin is. Citrix's bulletin carries a Sept. 27 initial-publication date, while Help Net Security gives Sept. 29 for the patches, which would leave an agency one day between the fixed builds and the Sept. 30 deadline. The sources do not agree on that date, so the one-day figure is a possibility and not a finding.
The Cisco listing is the cleanest case. The advisory is dated Sept. 30, fixes exist for six release trains from 20.9.10.1 to 26.2.1, and Cisco offers no workaround, so a federal agency running the Manager has no option except to upgrade or isolate it. Fortinet's is the opposite: the advisory says the fixed builds are 8.0.2, 7.6.7 and 7.4.9, and a 7.2 appliance has no fix at all on its own branch.
Patch first, or look first
The directive's second step is blunt: "Do not alter or remediate systems prior to evidence/artifact collection when possible." CISA's Citrix alert says the same in operational terms, urging organizations to check for indications of compromise before patching, because updates may affect forensic visibility.
The Citrix case shows why that matters. Unit 42 dated exploitation to Sept. 4 through Sept. 24, before Citrix published anything, and warned that patching does not remove an attacker who has already persisted. Cisco's advisory points to two log files to search, and Fortinet's lists seven file paths and two IP addresses.
An agency with a few dozen exposed appliances has three days to image logs, search them, rebuild or upgrade, and report. The CSA note quotes Tod Beardsley of runZero expressing "doubt that a three-day deadline is achievable across more than a hundred federal agencies."
What the pilot data says
The CSA note reports that in pilot data about 1 percent of tracked vulnerabilities fell into the three-day tier and 60 percent qualified for deferral. It cites a median remediation time of 43 days for KEV vulnerabilities in 2025. If both figures hold, the three-day tier is rare by design, and these three appliance flaws are the rare case it was built for. The CSA authors also write that "exploitation increasingly arriving in hours rather than weeks."
What would show the directive working is an agency-level count of how many of the three listings were closed inside their windows. CISA has not published one, and the fetched pages give no sign it will. What can be checked now is smaller: whether Fortinet's 8.0.2, 7.6.7 and 7.4.9 builds are downloadable before the reported Oct. 4 deadline, since Suped warns they may not be.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Monta's EV Charging Platform Has No Patch for a 9.4 Authentication GapCISA lists four flaws in monta.app, all versions. The vendor points operators to an optional OCPP security profile and has shipped no fix.