Home / Sep 11, 2026 / Story
0
#6 The Hacker News general September 10, 2026 at 10:36 UTC

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

By [email protected] (The Hacker News)

AI Summary

CISA added three actively exploited vulnerabilities to its KEV catalog on September 10, 2026, covering Cisco (CVE-2026-20079, CVSS 10.0 authentication bypass), Citrix (NetScaler), and Fortinet (CVE-2025-25249, unauthenticated RCE patched January 2026), with a mandatory federal patch deadline of September 12, 2026. The Fortinet flaw is being used to deploy the PivotC2 RAT, while the Cisco and Citrix flaws are under active exploitation by ransomware and state-sponsored actors. The two-day remediation window for federal agencies underscores the severity of the threat across all three vendors.

Relevance score: 83.0/100

# More from September 11