CISA Adds Cisco FMC, Citrix NetScaler and FortiOS Flaws to Exploited List
Security / news
CISA Adds Cisco FMC, Citrix NetScaler and FortiOS Flaws to Exploited List
The 10.0 is the clearest case; the Citrix 9.3 depends on configuration; the Fortinet 7.3 understates an active RAT campaign.

Three network appliances that sit in front of everything else were added to CISA's Known Exploited Vulnerabilities catalogue on September 9: Cisco Secure Firewall Management Center (CVE-2026-20079, CVSS 10.0), Citrix NetScaler (CVE-2026-19490, CVSS 9.3) and Fortinet FortiOS (CVE-2025-25249, CVSS 7.3). All three can be attacked without credentials, and Citrix shipped its fix on August 19.
CISA's alert also lists a fourth entry, a Google Chromium V8 out-of-bounds write (CVE-2026-87491). None of the sources we read covers that one in detail, so it is not assessed here. The Hacker News reports a federal patch deadline of September 12 for the other three.

Cisco FMC: the highest score, the clearest preconditions
CVE-2026-20079 is an authentication bypass in the web interface of Cisco Secure Firewall Management Center. An unauthenticated remote attacker can run script files on the device and reach root on the underlying operating system. The precondition is reachability of the web interface, which on a management plane should never face the internet.
The score of 10.0 is earned, because the target is the console that manages the firewalls. The Hacker News reports that exploitation has been under way since August 2026 and that Cisco has identified three post-compromise clusters, tracked as UAT-12197, UAT-11823 and UAT-11988, which left web shells and other malware.
Citrix NetScaler: patched August 19, exploited by September 4
Field Effect's analysis puts the timeline in order: Citrix shipped fixes on August 19, public proof-of-concept code appeared in early September, and active exploitation was confirmed on September 4. Affected builds are NetScaler ADC and Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, including the FIPS and NDcPP variants.
The score overstates the exposure for some estates. Only appliances configured as a Gateway (SSL VPN, ICA Proxy, clientless VPN, RDP Proxy) or as an AAA virtual server are at risk, and on newer releases exploitation also needs SAML authentication to be configured. An appliance that terminates remote-access logins is the target.
The Hacker News counts 56 honeypot attempts since September 3, 36 of them on September 8 alone. It does not name whose honeypot recorded them, so treat the figure as indicative.
Fortinet: the score that understates
CVE-2025-25249 is a heap-based buffer overflow in FortiOS, FortiSwitchManager and FortiSASE. The 7.3 rating reads as moderate. It understates the situation: a remote unauthenticated attacker can execute code with crafted requests, and The Hacker News reports it has been weaponised since July 2026 in a campaign that delivers a remote access trojan called PivotC2.
That report puts the campaign at more than 3,000 targeted IP addresses and 178 infected devices, mostly in the United States, and attributes it to a Russian-speaking, financially motivated actor. Those numbers come from a single outlet and we could not check them against a primary report.
| Product | CVE | CVSS | What the attacker needs |
|---|---|---|---|
| Cisco Secure FMC | CVE-2026-20079 | 10.0 | Network reach to the web interface |
| Citrix NetScaler | CVE-2026-19490 | 9.3 | Gateway or AAA configuration; SAML on newer builds |
| Fortinet FortiOS | CVE-2025-25249 | 7.3 | Ability to send crafted requests |
- Cisco FMC CVE-2026-2007910 CVSS
- Citrix NetScaler CVE-2026-194909.3 CVSS
- Fortinet FortiOS CVE-2025-252497.3 CVSS
Source: The Hacker News, accessed 2026-09-30
What to do
Patch NetScaler to 14.1-73.32 or 13.1-63.21 or later, and confirm whether the appliance runs as a Gateway or AAA server before deciding how urgent it is. Take any Cisco FMC web interface off the internet and apply Cisco's fix. For FortiOS, apply the vendor update and look for signs of PivotC2 rather than relying on the moderate score.
CISA's catalogue is also where we have tracked three Linux kernel CVEs and their score gap and Apple's CoreGraphics zero-day.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.