HackMyIP
← Back to News
2026-09-10 The Hacker News

CISA Orders Federal Agencies to Patch Cisco, Citrix, Fortinet Exploits

VulnerabilityAPTThreat Intel

CISA added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, setting a September 12, 2026 remediation deadline for Federal Civilian Executive Branch agencies. The flaws include CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center with a maximum CVSS score of 10.0 that allows unauthenticated remote attackers to execute script files and obtain root access to the underlying operating system. CVE-2026-19490 (CVSS 9.3) is a second authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway when configured as an AAA virtual server or as a Gateway, while CVE-2025-25249 (CVSS 7.3) is a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE enabling arbitrary code execution through crafted requests.

Cisco updated its advisory for CVE-2026-20079 to confirm active exploitation detected in August 2026, though the company declined to share additional details. The disclosure aligns with recent reporting from Sygnia on the China-linked "Fire Ant" espionage group compromising Cisco IOS XR routers and converting them into surveillance platforms for persistence, data collection, and lateral movement inside high-value networks. On the Citrix side, threat intelligence from Previdian's honeypot infrastructure recorded 56 exploitation attempts against CVE-2026-19490 since September 3, with 36 attempts concentrated on September 8 alone, signaling organized targeting activity.

The Fortinet vulnerability has been weaponized by a financially motivated Russian-speaking threat actor to deploy PivotC2, a Node.js-based remote access trojan featuring interactive shells, tunneling, network scanning, and configuration harvesting capabilities. SOCRadar estimates the campaign reached over 3,000 IP addresses, infecting 178 devices primarily located in the United States. Security teams operating affected Cisco, Citrix, or Fortinet appliances should prioritize patching immediately, audit internet-exposed management interfaces using a port scanner to identify vulnerable services, and validate VPN appliance certificate configurations with an SSL/TLS checker.

Given that two of the three flaws are authentication bypasses, administrators should also rotate all privileged credentials and run a password checker to confirm no compromised or weak credentials remain in use across the environment.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →