CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
By [email protected] (The Hacker News)
AI Summary
CISA added three actively exploited vulnerabilities to its KEV catalog on September 10, 2026, covering Cisco (CVE-2026-20079, CVSS 10.0 authentication bypass), Citrix (NetScaler), and Fortinet (CVE-2025-25249, unauthenticated RCE patched January 2026), with a mandatory federal patch deadline of September 12, 2026. The Fortinet flaw is being used to deploy the PivotC2 RAT, while the Cisco and Citrix flaws are under active exploitation by ransomware and state-sponsored actors. The two-day remediation window for federal agencies underscores the severity of the threat across all three vendors.
Relevance score: 83.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →