CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws

CISA added three actively exploited vulnerabilities in Cisco, Citrix, and Fortinet products to its KEV catalog on September 10, requiring federal agencies to patch by September 12.
Table of Contents
    Add a header to begin generating the table of contents

    The US Cybersecurity and Infrastructure Security Agency added three actively exploited vulnerabilities impacting Cisco Secure Firewall Management Center, Citrix NetScaler, and Fortinet products to its Known Exploited Vulnerabilities catalog on September 10, setting a September 12 deadline for Federal Civilian Executive Branch agencies to apply patches. All three flaws are confirmed to be under active exploitation in the wild, with CVE-2026-20079 in Cisco FMC receiving a CVSS score of 10.0 — the highest severity rating.

    CVE-2026-20079 Enables Unauthenticated Remote Code Execution on Cisco FMC

    CVE-2026-20079, the critical vulnerability in Cisco Secure Firewall Management Center, combines authentication bypass with remote code execution capabilities. An unauthenticated attacker can exploit the flaw to execute arbitrary code on vulnerable Cisco FMC systems without needing any prior credentials or user interaction. The CVSS 10.0 score reflects the flaw’s network accessibility, lack of authentication requirement, and full system compromise outcome.

    Federal Agencies Must Patch by September 12 Under Binding Operational Directive

    CISA’s inclusion of these vulnerabilities in the KEV catalog triggers a binding operational directive requiring Federal Civilian Executive Branch agencies to patch affected systems by September 12. The two-day remediation window is among the shortest CISA has issued for a multi-vendor batch, reflecting the combination of active exploitation, critical severity, and widespread deployment of the affected products in federal networks.

    Active Exploitation Confirmed Across Cisco, Citrix, and Fortinet Vulnerabilities

    CISA confirmed active exploitation for all three vulnerabilities added to the KEV catalog. Active exploitation means adversaries already possess working exploits and are targeting vulnerable systems in the wild. Organizations running the affected Cisco, Citrix, or Fortinet products face immediate risk from attackers who have demonstrated both capability and intent to exploit these specific flaws.

    Urgent Patching Required for Federal Networks and Private Sector Deployments

    Federal agencies face compliance requirements under CISA’s binding operational directive, but private sector organizations running the same Cisco, Citrix, and Fortinet products face equivalent technical risk. The KEV catalog serves as CISA’s signal that exploitation is widespread and not limited to targeted attacks against specific industries or regions.

    The Known Exploited Vulnerabilities catalog represents CISA’s authoritative list of flaws confirmed to be exploited in the wild that pose significant risk to federal networks. KEV inclusion triggers binding operational directives for federal agencies, but CISA also publishes the catalog as guidance for private sector organizations to prioritize their own patching efforts. When CISA adds vulnerabilities to the KEV catalog, it signals that adversaries have demonstrated both capability and intent to exploit those specific flaws at scale.

    Cisco, Citrix, and Fortinet have released patches for the listed vulnerabilities. Organizations should prioritize these patches above normal change management cycles, particularly for internet-facing appliances and systems that handle authentication or network segmentation. The authentication bypass nature of CVE-2026-20079 and the similar authentication weaknesses in the Citrix and Fortinet flaws mean that traditional perimeter defenses cannot prevent exploitation — the vulnerabilities exist in the perimeter devices themselves.

    The two-day federal remediation window from September 10 to September 12 is exceptionally short compared to typical KEV deadlines, which often allow one to two weeks. This compressed timeline reflects CISA’s assessment that the vulnerabilities present critical and imminent risk to federal networks, likely based on intelligence indicating active targeting of government systems or widespread exploitation that has already compromised numerous organizations.

    Security teams that cannot immediately patch should implement network-level isolation for vulnerable appliances, restrict management interface access to trusted networks only, and monitor for indicators of compromise consistent with the known exploitation patterns. The September 12 federal deadline establishes a de facto industry standard for how quickly these flaws must be addressed to maintain acceptable risk posture.

    Related Posts