🔴 Critical: CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, each affecting a different vendor: Cisco, Citrix, and Fortinet. Federal Civilian Executive Branch (FCEB) agencies are required to apply the corresponding patches by September 12, 2026.
The vulnerabilities flagged are:
- CVE-2026-20079 (CVSS score: 10.0) — an authentication issue in a Cisco product.
The article notes that this Cisco flaw carries the maximum severity rating, underscoring the urgency of remediation for exposed systems. CISA's KEV designation means the vulnerability is confirmed to be exploited in the wild, not merely theoretical, which is why the binding patch deadline applies to federal agencies.
Details on the Citrix and Fortinet vulnerabilities, including their specific identifiers, were not provided in the source material. Organizations running any of the three vendors' affected products should track vendor advisories directly and prioritize patching ahead of the federal deadline.
Source: The Hacker News
Does your organization run any Cisco, Citrix, or Fortinet products that could be affected by these KEV additions?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login