[CRITICAL] "CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline"
criticalDetails
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to patch three actively exploited vulnerabilities, setting a firm deadline. The most critical of these is CVE-2026-20079, a perfect 10.0 CVSS score authentication bypass in Cisco's Secure Firewall Management Center (FMC). The inclusion in the KEV catalog confirms active, ongoing attacks against this vulnerability.
Affected Systems
Cisco Secure Firewall Management Center (FMC), Citrix NetScaler, and unspecified Fortinet appliances.
Potential Impact
Successful exploitation allows for complete takeover of central firewall management systems, leading to network-wide compromise, data exfiltration, and deployment of ransomware. The CISA directive indicates a high risk to federal and critical infrastructure networks.
Mitigations
Per CISA's directive, all Federal Civilian Executive Branch agencies must apply vendor patches for CVE-2026-20079 and CVE-2026-19490 by September 12, 2026. All organizations using the affected products should prioritize installing these security updates immediately.