The U.S. Cybersecurity and Infrastructure Security Agency has added three actively exploited vulnerabilities affecting Cisco, Citrix and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog, signalling that the flaws are no longer theoretical risks. Federal Civilian Executive Branch agencies have been ordered to address the vulnerabilities by September 12, 2026, putting additional pressure on organisations running affected products to patch or mitigate them immediately.
The newly listed issues affect security and networking products that are often deployed at the perimeter of enterprise environments, including Cisco Secure Firewall Management Center, Citrix NetScaler appliances and several Fortinet platforms. That makes the situation particularly serious, because vulnerabilities in externally exposed infrastructure can provide attackers with an entry point before they ever need to compromise an internal workstation.
Three High-Risk Vulnerabilities Now Under Active Exploitation
The first flaw, CVE-2026-20079, carries the maximum CVSS score of 10.0 and affects the web interface of Cisco Secure Firewall Management Center, or FMC. The vulnerability can allow a remote, unauthenticated attacker to bypass authentication and execute script files on a vulnerable appliance.
If exploited successfully, the attacker may obtain root access to the underlying operating system, giving them an extremely high level of control over the affected device. Given the role FMC plays in centrally managing firewall infrastructure, a compromise at this level could have consequences extending well beyond a single system.
Cisco has since updated its advisory to confirm that it became aware of active exploitation targeting the vulnerability in August 2026. The company has not publicly released many additional details about those attacks, but CISA's decision to add the flaw to the KEV catalog indicates that exploitation has been sufficiently verified to warrant urgent remediation.
Citrix NetScaler Flaw Also Seeing Real-World Attack Activity
The second vulnerability, CVE-2026-19490, affects Citrix NetScaler ADC and NetScaler Gateway and has been assigned a CVSS score of 9.3. The issue can allow authentication bypass when an affected appliance is configured as an AAA virtual server or deployed as a Gateway using features such as SSL VPN, ICA Proxy, CVPN or RDP Proxy.
Those deployment scenarios are common in environments where employees or contractors access corporate resources remotely, which makes internet-exposed NetScaler appliances particularly attractive targets. A vulnerability that weakens authentication at the gateway layer can potentially give attackers a much easier path toward sensitive internal services.
Evidence suggests that exploitation attempts are already underway. Previdian reportedly observed 56 attempts against its honeypot infrastructure since September 3, 2026, with 36 of those attempts occurring on September 8 alone.
That concentration of activity suggests that attackers are actively scanning for vulnerable systems rather than simply experimenting with proof-of-concept code.
Fortinet Flaw Linked to PivotC2 Campaign
The third issue, CVE-2025-25249, affects FortiOS, FortiSwitchManager and FortiSASE. It has a lower CVSS score of 7.3, but real-world exploitation demonstrates why severity scores should never be considered in isolation.
The vulnerability is a heap-based buffer overflow that can allow an unauthenticated remote attacker to execute arbitrary code or commands by sending specially crafted requests. CISA added the flaw to the KEV catalog following reporting that linked it to a malicious campaign delivering a Node.js-based remote access Trojan known as PivotC2.
The campaign appears to have targeted more than 3,000 IP addresses, with at least 178 devices reportedly infected. Most of the confirmed compromises were concentrated in the United States, while researchers assessed the activity as likely being conducted by a Russian-speaking threat actor primarily motivated by financial gain.
Evidence suggests exploitation may have been taking place since July 2026, meaning some organisations could have been exposed for weeks before the vulnerability received broader attention through CISA's catalog.
How the Fortinet Attacks Work
The observed attack chain begins with a shell script containing an exploit binary designed to target a vulnerable FortiGate device. Successful exploitation establishes a reverse shell, giving the attacker the ability to execute commands remotely.
From there, the attackers reportedly use a short JavaScript command executed through Node.js to download a second-stage payload. That JavaScript payload is then decrypted and executed, ultimately installing PivotC2 on the compromised system.
PivotC2 is more than a basic backdoor. According to researchers, it provides a fairly extensive post-compromise toolkit, including interactive command shells, file transfers, SOCKS5 and HTTP proxy tunnelling, port forwarding, network scanning and configuration harvesting.
It can also target FortiGate-specific information, including configuration data and encrypted credentials, making it particularly dangerous in environments where the compromised device controls or monitors access to other parts of the network.
PivotC2 Can Turn a Firewall Into a Stepping Stone
Once active, PivotC2 establishes a persistent outbound TLS connection to a command-and-control server. That encrypted channel allows attackers to maintain access while sending instructions to the compromised appliance.
Its tunnelling and port-forwarding capabilities are especially important because they can allow an attacker to use the compromised Fortinet device as a pivot point into internal systems that would otherwise be inaccessible from the internet.
The framework also includes an automatic mode capable of running predefined command sequences as soon as a device is compromised. This can make exploitation faster and reduce the amount of manual interaction required from the attacker.
In practical terms, a perimeter device that was supposed to protect the network can instead become the infrastructure attackers use to explore it.
Cisco Routers Continue to Attract State-Linked Threat Groups
The latest Cisco vulnerability also arrives against a backdrop of increasing interest in routers and network infrastructure from advanced threat groups.
Security firm Sygnia recently reported activity involving a China-linked cyber-espionage group tracked as Fire Ant, which was observed compromising Cisco IOS XR routers. The attackers reportedly used those devices to maintain persistence, collect information and move deeper into valuable enterprise environments.
What makes router compromises particularly dangerous is their position in the network. These devices already sit in trusted paths through which large amounts of traffic pass, giving attackers a powerful vantage point once they gain control.
Rather than merely forwarding packets, a compromised router can effectively become a surveillance platform, allowing a threat actor to observe or manipulate traffic that would otherwise appear to be moving through legitimate infrastructure.
This is one reason attackers increasingly focus on edge devices such as firewalls, VPN gateways and routers. These systems are often internet-facing, highly privileged and less closely monitored than ordinary endpoints.
Why Edge Devices Have Become Such Attractive Targets
Modern enterprises devote significant resources to endpoint security. Laptops and desktops may have EDR agents, antivirus, detailed telemetry and multiple layers of behavioural monitoring.
Network appliances are often different.
Firewalls, VPN gateways, routers and other perimeter systems may not provide the same level of logging or telemetry, and in some environments they are managed by smaller teams or left unchanged for long periods after deployment. That creates an opportunity for attackers who can find an unpatched vulnerability.
Edge devices are also appealing because compromising one can potentially bypass many of the protections designed to keep attackers out.
A vulnerable internet-facing firewall or VPN appliance may give an adversary access before they ever need to send a phishing email or trick a user into launching malware.
CISA's KEV Catalog Is More Than a Vulnerability List
CISA's Known Exploited Vulnerabilities catalog is intended to highlight security flaws that have confirmed evidence of exploitation in the wild. That distinction is important because thousands of new vulnerabilities are disclosed every year, but only a smaller number become active tools for attackers.
When a flaw appears in the KEV catalog, organisations know that the risk is no longer hypothetical.
For U.S. Federal Civilian Executive Branch agencies, the consequences are even more direct. Agencies covered by CISA's Binding Operational Directive must remediate listed vulnerabilities within the required timeframe.
In this case, the deadline is September 12, 2026.
Private organisations are not legally bound by the same federal directive, but the KEV catalog is still widely used as a patch-prioritisation resource. If a vulnerability affecting internet-facing infrastructure has already been exploited, it generally deserves much higher priority than an equally severe flaw with no known exploitation.
CVSS Scores Do Not Tell the Whole Story
The three vulnerabilities also demonstrate why security teams should avoid relying on CVSS scores alone.
Cisco's CVE-2026-20079 carries a perfect score of 10.0, while the Citrix issue is rated 9.3. The Fortinet vulnerability sits notably lower at 7.3.
Yet the Fortinet flaw has reportedly been used in a campaign that compromised real devices and deployed a capable remote access Trojan.
That is a useful reminder that a vulnerability's practical risk depends on much more than its numerical severity score. Exposure, exploit availability, attacker interest, deployment patterns and the role of the affected system all matter.
A medium-to-high vulnerability actively being exploited against publicly accessible devices can be far more urgent than a technically critical flaw buried inside a system attackers cannot realistically reach.
Organisations Should Treat Perimeter Patching as an Emergency Task
The common thread across all three vulnerabilities is that they affect systems sitting close to the edge of the network.
That means organisations should first determine whether vulnerable Cisco, Citrix or Fortinet products are exposed directly to the internet. If they are, remediation should be treated as a high-priority task rather than waiting for a routine patch cycle.
Simply applying updates is not necessarily enough, either. If a device has already been compromised, patching the vulnerability closes the entry point but does not automatically remove attacker persistence or malware that may already be present.
Security teams should therefore combine patching with compromise assessment.
That can include examining logs, looking for unusual administrative activity, reviewing outbound connections, checking newly created accounts and searching for known indicators associated with the observed campaigns.
Credential Rotation May Be Necessary After Fortinet Compromise
SOCRadar has specifically advised Fortinet customers to consider several additional defensive steps beyond patching.
Organisations should reduce unnecessary internet exposure, review systems for indicators of compromise and rotate credentials that may have been accessible through a vulnerable appliance.
Credential rotation is particularly important when malware such as PivotC2 has the ability to harvest FortiGate configurations or recover stored authentication information.
If attackers have already obtained those credentials, simply removing the malware may not be enough. They could potentially return through other services using previously stolen authentication material.
A broader incident response process may therefore be necessary for systems showing signs of exploitation.
Reducing Internet Exposure Can Limit Future Risk
The recurring exploitation of networking appliances also reinforces a basic security principle: administrative interfaces should not be exposed to the internet unless absolutely necessary.
Where possible, management access should be restricted to dedicated administrative networks, VPN connections or tightly controlled IP ranges.
Multi-factor authentication should also be used wherever the product supports it, although an authentication-bypass vulnerability can sometimes undermine even strong login protections.
Network segmentation can provide another layer of defence. If a firewall, VPN appliance or management server is compromised, it should not automatically give attackers unrestricted access to every internal system.
The goal is not simply to prevent the initial exploit but to limit how far an attacker can go if that first layer fails.
Monitoring Network Appliances Needs to Improve
The latest campaigns also highlight a longstanding visibility gap in many organisations.
Endpoint devices typically generate large amounts of security telemetry, while routers and security appliances may receive comparatively little monitoring. Attackers know this and often try to establish persistence in places where defenders are less likely to notice.
Logs from firewalls, VPN gateways and network management appliances should therefore be forwarded to central security platforms where suspicious activity can be correlated with events from other systems.
Unexpected outbound connections from appliances deserve particular attention. A firewall or router communicating persistently with an unfamiliar external server can be a strong indication that something is wrong.
Firmware integrity, unusual configuration changes and newly created administrative accounts are also valuable signals when investigating possible compromise.
The Window Between Disclosure and Exploitation Keeps Shrinking
Another concerning pattern is how quickly threat actors increasingly move from vulnerability disclosure to active exploitation.
Automated scanners can identify internet-facing products almost immediately, while exploit code can spread rapidly across criminal communities. Once attackers know that a widely deployed perimeter product contains a remotely exploitable flaw, mass scanning can begin very quickly.
That leaves organisations with far less time to patch than traditional monthly maintenance cycles were designed around.
For exposed infrastructure, patch management increasingly needs to be driven by threat intelligence and exploitation evidence rather than a fixed calendar.
CISA's KEV catalog is particularly useful in that context because it identifies vulnerabilities attackers are already using rather than vulnerabilities that merely might become dangerous someday.
Final Thoughts
CISA's latest additions to the Known Exploited Vulnerabilities catalog reinforce a familiar but increasingly urgent lesson: internet-facing network infrastructure remains one of the most valuable targets available to attackers.
Cisco Secure Firewall Management Center, Citrix NetScaler and Fortinet platforms all occupy trusted positions inside enterprise networks. When vulnerabilities in these products allow authentication bypass or remote code execution, attackers may gain control over systems that were originally deployed to protect everything behind them.
The September 12 deadline gives U.S. federal agencies only a short period to respond, but private organisations should not treat that date as something relevant only to government networks. Confirmed exploitation means attackers are already looking for vulnerable systems now.
For organisations running affected products, the priority should be clear: identify exposed devices, apply the latest patches or mitigations, investigate for signs of compromise, restrict unnecessary internet access and rotate credentials where appropriate.
The broader lesson is just as important. Firewalls, routers and VPN gateways cannot be treated as invisible infrastructure that only needs attention when something stops working. As attackers increasingly turn these devices into persistence points, surveillance platforms and pivots into internal networks, monitoring and patching them needs to become just as routine—and just as urgent—as protecting the endpoints they were designed to defend.


Comments 0