{"id":18586,"date":"2026-09-10T12:45:28","date_gmt":"2026-09-10T12:45:28","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=18586"},"modified":"2026-09-10T12:45:28","modified_gmt":"2026-09-10T12:45:28","slug":"cisa-flags-exploited-cisco-citrix-fortinet-flaws-units-sept-12-federal-patch-deadline","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=18586","title":{"rendered":"CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Units Sept. 12 Federal Patch Deadline"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 10, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Community Safety<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh7j6Sm8OqDeYzrbb5faLBuDOc0zIMlvfjiKbn1aCMpx_2iBl6gb3HhJhpbqU8SPajHUClJEXUwnFbY1DcubmzWeVaWCyGcHkw45rCYqU_4IFO_g4OwdyNrTFFK3l3YsXwfOWQj2QtW3UTeglKmyRJ4GvbVKMxLTByMgeZ7E0WWpxpi50qie2lx9DbCY9rr\/s1600\/cisa-list.jpg\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"0\" data-original-width=\"0\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh7j6Sm8OqDeYzrbb5faLBuDOc0zIMlvfjiKbn1aCMpx_2iBl6gb3HhJhpbqU8SPajHUClJEXUwnFbY1DcubmzWeVaWCyGcHkw45rCYqU_4IFO_g4OwdyNrTFFK3l3YsXwfOWQj2QtW3UTeglKmyRJ4GvbVKMxLTByMgeZ7E0WWpxpi50qie2lx9DbCY9rr\/s1600\/cisa-list.jpg\"\/><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Wednesday <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/09\/cisa-adds-four-known-exploited-vulnerabilities-catalog\" target=\"_blank\">added<\/a> three flaws, every impacting Cisco, Citrix, and Fortinet, to its Identified Exploited Vulnerabilities (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, requiring Federal Civilian Government Department (FCEB) companies to use the patches by September 12, 2026.<\/p>\n<p>The vulnerabilities are listed under &#8211;<\/p>\n<ul>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/07\/cisco-fmc-zero-day-actively-exploited.html\" target=\"_blank\">CVE-2026-20079<\/a><\/strong> (CVSS rating: 10.0) &#8211; An authentication bypass vulnerability within the net interface of Cisco Safe Firewall Administration Heart (FMC) Software program that might enable an unauthenticated, distant attacker to bypass authentication and execute script information on an affected system to acquire root entry to the underlying working system.<\/li>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/08\/critical-netscaler-flaw-can-bypass.html\" target=\"_blank\">CVE-2026-19490<\/a><\/strong> (CVSS rating: 9.3) &#8211; An authentication bypass vulnerability in\u00a0 Citrix NetScaler ADC and NetScaler Gateway when the equipment is configured as an AAA digital server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).<\/li>\n<li><strong><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/fortiguard.fortinet.com\/psirt\/FG-IR-25-084\" target=\"_blank\">CVE-2025-25249<\/a><\/strong> (CVSS rating: 7.3) &#8211; A heap-based buffer overflow vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that might enable a distant unauthenticated attacker to execute arbitrary code or instructions through particularly crafted requests.<\/li>\n<\/ul>\n<p>The event comes as Cisco <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-onprem-fmc-authbypass-5JPp45V2\" target=\"_blank\">up to date its advisory<\/a> for CVE-2026-20079 to notice that it grew to become conscious of energetic exploitation efforts concentrating on the flaw in August 2026. It didn&#8217;t disclose any extra particulars.<\/p>\n<p><!--adsense--><\/p>\n<p>Cisco routers have been an assault magnet in recent times. In a report printed late final month, Sygnia <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/08\/china-linked-fire-ant-hijacks-cisco.html\" target=\"_blank\">mentioned<\/a> it noticed a China-nexus cyber espionage group dubbed Fireplace Ant acquiring unauthorized entry to Cisco IOS XR routers and abusing them to facilitate persistence, knowledge assortment, and burrow deeper into high-value networks through customized malware.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" name=\"more\"\/><\/p>\n<p>&#8220;This conduct shifts the router&#8217;s function from a transit system to a set platform,&#8221; the cybersecurity firm famous. &#8220;As soon as the actor managed the router, the system grew to become a vantage level for observing site visitors shifting via trusted community paths.&#8221;<\/p>\n<p>CVE-2026-19490, then again, has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/08\/critical-netscaler-flaw-can-bypass.html#update\" target=\"_blank\">witnessed<\/a> exploitation exercise concentrating on Previdian&#8217;s honeypot programs, with a complete of 56 makes an attempt registered since September 3, 2026. Of those, 36 makes an attempt had been <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/previdian.com\/CVE-2026-19490\" target=\"_blank\">recorded<\/a> on September 8, 2026, alone.<\/p>\n<p>The addition of CVE-2025-25249 to the KEV catalog follows a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/socradar.io\/blog\/cve-2025-25249-pivotc2-fortigate-rat\/\" target=\"_blank\">report<\/a> from SOCRadar a few malicious assault marketing campaign that is suspected to have weaponized the flaw to ship a feature-rich Node.js distant entry trojan (RAT) codenamed PivotC2. The post-exploitation framework helps options equivalent to interactive shells, tunneling, community scanning, and configuration harvesting.<\/p>\n<p>Greater than 3,000 IP addresses are estimated to have been focused as a part of the marketing campaign, ensuing within the an infection of 178 gadgets with PivotC2. The vast majority of the compromises are concentrated within the U.S. The exercise is assessed to be the work of a Russian-speaking menace actor pushed by monetary achieve. The earliest proof of energetic exploitation of the flaw dates again to July 2026.<\/p>\n<p><!--linkads--><\/p>\n<p>Within the noticed assaults, a shell script containing an exploit binary targets a weak FortiGate occasion to determine a reverse shell and run a single-line JavaScript command through Node.js. This, in flip, results in the obtain of a second-stage JavaScript payload, which is decrypted and executed to ship PivotC2.<\/p>\n<p>&#8220;PivotC2 establishes a persistent outbound TLS connection to a distant command-and-control (C2) server. Its characteristic set consists of interactive shells, file transfers, SOCKS5\/HTTP proxy tunneling, native and distant port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption,&#8221; SOCRadar mentioned. &#8220;An auto-mode flag allows autonomous operations, robotically operating a predefined command sequence upon preliminary an infection.&#8221;<\/p>\n<p>The findings as soon as once more display that menace actors are constantly scanning uncovered perimeter edge gadgets to acquire preliminary entry by profiting from their lack of strong monitoring or telemetry logging. SOCRadar is recommending organizations utilizing Fortinet merchandise to restrict web entry, hunt for indicators of compromise, rotate credentials, and apply the most recent patches.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 10, 2026Vulnerability \/ Community Safety The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Wednesday added three flaws, every impacting Cisco, Citrix, and Fortinet, to its Identified Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Government Department (FCEB) companies to use the patches by September 12, 2026. The vulnerabilities are listed under &#8211; CVE-2026-20079 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":18588,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1359,131,4987,866,1994,2884,9366,1812,4021,1077,5109,3943],"class_list":["post-18586","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cisa","tag-cisco","tag-citrix","tag-deadline","tag-exploited","tag-federal","tag-flags","tag-flaws","tag-fortinet","tag-patch","tag-sept","tag-sets"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18586"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18586\/revisions"}],"predecessor-version":[{"id":18587,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18586\/revisions\/18587"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/18588"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}