<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline]]></title><description><![CDATA[<p dir="auto">The U.S. Cybersecurity and Infrastructure Security Agency (<strong>CISA</strong>) has added three actively exploited flaws to its Known Exploited Vulnerabilities (<strong>KEV</strong>) catalog, each affecting a different vendor: <strong>Cisco</strong>, <strong>Citrix</strong>, and <strong>Fortinet</strong>. Federal Civilian Executive Branch (FCEB) agencies are required to apply the corresponding patches by <strong>September 12, 2026</strong>.</p>
<p dir="auto">The vulnerabilities flagged are:</p>
<ul>
<li><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20079" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-20079</a></strong> (CVSS score: <strong>10.0</strong>) — an authentication issue in a Cisco product.</li>
</ul>
<p dir="auto">The article notes that this Cisco flaw carries the maximum severity rating, underscoring the urgency of remediation for exposed systems. CISA's KEV designation means the vulnerability is confirmed to be exploited in the wild, not merely theoretical, which is why the binding patch deadline applies to federal agencies.</p>
<p dir="auto">Details on the Citrix and Fortinet vulnerabilities, including their specific identifiers, were not provided in the source material. Organizations running any of the three vendors' affected products should track vendor advisories directly and prioritize patching ahead of the federal deadline.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Does your organization run any Cisco, Citrix, or Fortinet products that could be affected by these KEV additions?</p>
]]></description><link>https://xploitlk.com/topic/285/critical-cisa-flags-exploited-cisco-citrix-fortinet-flaws-sets-sept.-12-federal-patch-deadline</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:50:09 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/285.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 10 Sep 2026 12:30:19 GMT</pubDate><ttl>60</ttl></channel></rss>