TechNewsReel
Live

CISA Orders Federal Patching of Critical Cisco, Citrix, and Fortinet Flaws

Federal agencies must secure perimeter devices by September 12 after CISA flagged three actively exploited vulnerabilities.

TechNewsReel Newsroom · September 10, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has added three critical vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian Executive Branch (FCEB) agencies are now mandated to patch these flaws by September 12, 2026.

On September 9, CISA flagged the vulnerabilities following evidence of active exploitation. The most severe is CVE-2026-20079, an authentication bypass in the Cisco Secure Firewall Management Center (FMC) that allows remote root access; this flaw carries a maximum CVSS score of 10.0. Additionally, CISA highlighted CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and Gateway with a CVSS score of 9.3. The third entry, CVE-2025-25249, is a remote code execution vulnerability in Fortinet products, including FortiOS and FortiSwitchManager, which has been used to deploy the PivotC2 remote access trojan (RAT).

The Rise of Edge Device Targeting

These additions come as threat actors increasingly target perimeter edge devices to gain initial network access. This trend is exemplified by the activities of the China-nexus group known as 'Fire Ant,' which has been hijacking Cisco IOS XR routers for espionage purposes. By compromising these devices, attackers can bypass traditional security layers and establish a foothold deep within a target's infrastructure.

Infrastructure as a Weapon

Because these vulnerabilities target firewalls and gateways—the primary line of defense for most organizations—the implications are severe. Authentication bypasses and remote code execution allow attackers to gain root-level privileges or establish long-term persistence. In the case of the Fortinet flaw, a Russian-speaking threat actor weaponized the vulnerability to infect 178 devices across more than 30,000 targeted IP addresses using the Node.js-based PivotC2 RAT.

Security firm Sygnia noted that such compromises fundamentally alter the nature of the hardware, stating that this behavior "shifts the router's role from a transit device to a collection platform." Essentially, the very tools meant to secure the network are transformed into tools for data exfiltration and espionage.

Next Steps for Administrators

Organizations outside the federal government are strongly urged to apply the relevant updates immediately, as the KEV listing confirms these flaws are being used in the wild. Security teams should prioritize the Cisco FMC and Citrix NetScaler patches due to their high CVSS scores and the potential for full system takeover. Monitoring for unauthorized access to edge devices remains critical as automated scanning for unpatched gateways continues to rise.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.