• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Units Sept. 12 Federal Patch Deadline

Aarav Kapoor by Aarav Kapoor
September 10, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananSep 10, 2026Vulnerability / Community Safety

The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Wednesday added three flaws, every impacting Cisco, Citrix, and Fortinet, to its Identified Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Government Department (FCEB) companies to use the patches by September 12, 2026.

The vulnerabilities are listed under –

  • CVE-2026-20079 (CVSS rating: 10.0) – An authentication bypass vulnerability within the net interface of Cisco Safe Firewall Administration Heart (FMC) Software program that might enable an unauthenticated, distant attacker to bypass authentication and execute script information on an affected system to acquire root entry to the underlying working system.
  • CVE-2026-19490 (CVSS rating: 9.3) – An authentication bypass vulnerability in  Citrix NetScaler ADC and NetScaler Gateway when the equipment is configured as an AAA digital server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
  • CVE-2025-25249 (CVSS rating: 7.3) – A heap-based buffer overflow vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that might enable a distant unauthenticated attacker to execute arbitrary code or instructions through particularly crafted requests.

The event comes as Cisco up to date its advisory for CVE-2026-20079 to notice that it grew to become conscious of energetic exploitation efforts concentrating on the flaw in August 2026. It didn’t disclose any extra particulars.

Cisco routers have been an assault magnet in recent times. In a report printed late final month, Sygnia mentioned it noticed a China-nexus cyber espionage group dubbed Fireplace Ant acquiring unauthorized entry to Cisco IOS XR routers and abusing them to facilitate persistence, knowledge assortment, and burrow deeper into high-value networks through customized malware.

“This conduct shifts the router’s function from a transit system to a set platform,” the cybersecurity firm famous. “As soon as the actor managed the router, the system grew to become a vantage level for observing site visitors shifting via trusted community paths.”

CVE-2026-19490, then again, has witnessed exploitation exercise concentrating on Previdian’s honeypot programs, with a complete of 56 makes an attempt registered since September 3, 2026. Of those, 36 makes an attempt had been recorded on September 8, 2026, alone.

The addition of CVE-2025-25249 to the KEV catalog follows a report from SOCRadar a few malicious assault marketing campaign that is suspected to have weaponized the flaw to ship a feature-rich Node.js distant entry trojan (RAT) codenamed PivotC2. The post-exploitation framework helps options equivalent to interactive shells, tunneling, community scanning, and configuration harvesting.

Greater than 3,000 IP addresses are estimated to have been focused as a part of the marketing campaign, ensuing within the an infection of 178 gadgets with PivotC2. The vast majority of the compromises are concentrated within the U.S. The exercise is assessed to be the work of a Russian-speaking menace actor pushed by monetary achieve. The earliest proof of energetic exploitation of the flaw dates again to July 2026.

Within the noticed assaults, a shell script containing an exploit binary targets a weak FortiGate occasion to determine a reverse shell and run a single-line JavaScript command through Node.js. This, in flip, results in the obtain of a second-stage JavaScript payload, which is decrypted and executed to ship PivotC2.

“PivotC2 establishes a persistent outbound TLS connection to a distant command-and-control (C2) server. Its characteristic set consists of interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, native and distant port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption,” SOCRadar mentioned. “An auto-mode flag allows autonomous operations, robotically operating a predefined command sequence upon preliminary an infection.”

The findings as soon as once more display that menace actors are constantly scanning uncovered perimeter edge gadgets to acquire preliminary entry by profiting from their lack of strong monitoring or telemetry logging. SOCRadar is recommending organizations utilizing Fortinet merchandise to restrict web entry, hunt for indicators of compromise, rotate credentials, and apply the most recent patches.

Tags: CISACiscoCitrixdeadlineExploitedfederalFlagsFlawsFortinetPatchSeptSets
Aarav Kapoor

Aarav Kapoor

Aarav Kapoor covers the latest in technology, gadgets, cybersecurity, software and smart home trends for TechTrendFeed. He breaks down complex tech news into clear, practical insights for everyday readers.

Next Post
Social Media Engagement: summer time 2026

Social Media Engagement: summer time 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

These 5 Easy Methods Helped Me Construct a Smarter House

These 5 Easy Methods Helped Me Construct a Smarter House

July 19, 2025
Discover a Software program Improvement Firm in Europe

Discover a Software program Improvement Firm in Europe

August 22, 2025
KV Cache Administration: PagedAttention & RadixAttention

KV Cache Administration: PagedAttention & RadixAttention

August 23, 2026
Consider any agent framework with Amazon Bedrock AgentCore Evaluations

Consider any agent framework with Amazon Bedrock AgentCore Evaluations

August 27, 2026
Submit Your Questions: The Nice Knowledge Heart Backlash

Submit Your Questions: The Nice Knowledge Heart Backlash

August 27, 2026

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

New methodology allows AI for safety-critical conditions | MIT Information

New methodology allows AI for safety-critical conditions | MIT Information

September 16, 2026
Samsung Goes to {Couples} Remedy to Unpack iPhone-to-Android Stress

Samsung Goes to {Couples} Remedy to Unpack iPhone-to-Android Stress

September 16, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved