CVE-2026-20079 (CVSS score: 10.0) is one of three vulnerabilities CISA added to its Known Exploited Vulnerabilities catalog and tied to a federal patching deadline of September 12, 2026.
CISA action and the September 12, 2026 federal deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three vulnerabilities—affecting Cisco, Citrix, and Fortinet—to its Known Exploited Vulnerabilities (KEV) catalog. The listing requires Federal Civilian Executive Branch (FCEB) agencies to apply patches for the three flaws by September 12, 2026.
The three entries are: CVE-2026-20079 (Cisco Secure Firewall Management Center), CVE-2026-19490 (Citrix NetScaler ADC and NetScaler Gateway), and CVE-2025-25249 (Fortinet FortiOS, FortiSwitchManager, and FortiSASE). CISA’s KEV additions impose a mandatory timeline for federal agencies, reflecting the agency’s assessment of active or likely exploitation risk for these specific defects.
Cisco: CVE-2026-20079 and evidence of active exploitation
CVE-2026-20079 is described as an authentication bypass in the web interface of Cisco Secure Firewall Management Center (FMC) Software that "could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system." The flaw carries a CVSS score of 10.0.
Cisco updated its advisory to note it "became aware of active exploitation efforts targeting the flaw in August 2026." The company did not disclose additional details about the exploitation activity in that advisory.
That development arrives amid independent reporting about router-focused intrusions. In a report published late last month, Sygnia said it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them for persistence, data collection, and deeper network access. As Sygnia summarized: "This behavior shifts the router's role from a transit device to a collection platform. Once the actor controlled the router, the device became a vantage point for observing traffic moving through trusted network paths."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCitrix: CVE-2026-19490 and observed probe activity
CVE-2026-19490 is an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway when configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy). The vulnerability carries a CVSS score of 9.3.
Exploit activity targeting this Citrix flaw has been observed against Previdian's honeypot systems. Previdian registered a total of 56 attempts since September 3, 2026; 36 of those attempts were recorded on September 8, 2026, alone. Those telemetry points are the specific exploitation indicators reported alongside the KEV addition.
Fortinet: CVE-2025-25249, PivotC2, and a large-scale campaign
CVE-2025-25249 is a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that could allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. The CVSS score listed is 7.3.
SOCRadar reported a malicious campaign that weaponized this Fortinet flaw to deliver a Node.js remote access trojan (RAT) codenamed PivotC2. According to SOCRadar, more than 3,000 IP addresses were targeted in the campaign and 178 devices were infected; the majority of compromises were concentrated in the U.S. SOCRadar assessed the actor as a Russian‑speaking, financially motivated threat actor, and said the earliest evidence of active exploitation dates back to July 2026.
SOCRadar described the observed attack chain: a shell script with an exploit binary targets a vulnerable FortiGate instance to establish a reverse shell and execute a single-line JavaScript command via Node.js. That command downloads a second-stage JavaScript payload, which is decrypted and executed to deliver PivotC2.
Details on PivotC2’s capabilities in SOCRadar’s write-up include a persistent outbound TLS connection to a remote command-and-control server; interactive shells; file transfers; SOCKS5/HTTP proxy tunneling; local and remote port forwarding; CIDR-range scanning; and FortiGate-specific configuration harvesting and credential decryption. An "auto-mode flag" enables autonomous operations that automatically run a predefined command sequence upon initial infection.
SOCRadar recommended that organizations using Fortinet products limit internet access to devices, hunt for indicators of compromise, rotate credentials, and apply the latest patches.
What this means for FCEB agencies, Fortinet customers, and enterprise security teams
- FCEB agencies: The KEV listing imposes a compliance requirement—patch the specified Cisco, Citrix, and Fortinet flaws by September 12, 2026. The Cisco advisory indicating active exploitation in August 2026 and the Citrix honeypot hits argue for immediate prioritization.
- Fortinet customers: SOCRadar’s observations tie CVE-2025-25249 to a widespread, commodity-style campaign delivering PivotC2; organizations using Fortinet devices are advised, per SOCRadar, to limit internet-facing access to appliances, hunt for compromise indicators, rotate credentials, and apply vendor patches.
- Enterprise security teams: The varied telemetry—active exploitation claims for Cisco, repeated honeypot probes against Citrix, and a multi-thousand‑IP Fortinet campaign—indicates perimeter network devices are actively scanned and targeted; teams should prioritize patching, look for the described command-and-control and JavaScript download behaviors, and validate logging and telemetry on edge appliances.
The KEV additions consolidate three concrete, high‑risk attack vectors into a single, time‑bound remediation task: federal agencies must patch by September 12, 2026, and private-sector operators of Cisco, Citrix, and Fortinet appliances face documented and active exploitation patterns tied to all three entries. The record in the advisories and third‑party reports leaves no ambiguity about where immediate defensive effort should be concentrated—hardening and patching edge devices, hunting for the described indicators, and limiting unnecessary internet exposure until fixes are deployed.
https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html




