CISA Adds Critical Cisco, Citrix, and Fortinet Flaws to KEV Catalog Amidst Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has issued a critical directive, adding three significant vulnerabilities impacting **Cisco**, **Citrix**, and **Fortinet** products to its Known Exploited Vulnerabilities (**KEV**) catalog. Federal Civilian Executive Branch (**FCEB**) agencies are mandated to patch these flaws by September 12, 2026, as evidence of active exploitation mounts across all three.

**CISA**'s latest update to the **KEV** catalog highlights three actively exploited vulnerabilities that demand immediate attention from IT security professionals. The inclusion of these flaws underscores the urgent need for organizations to prioritize patching and bolster their defenses against persistent threat actors.
### The Critical Vulnerabilities
The newly added vulnerabilities are:
* **CVE-2026-20079** (CVSS score: 10.0): An authentication bypass flaw in the web interface of **Cisco Secure Firewall Management Center (FMC)** Software. This allows an unauthenticated, remote attacker to gain root access to the underlying operating system by bypassing authentication and executing script files.
* **CVE-2026-19490** (CVSS score: 9.3): An authentication bypass vulnerability affecting **Citrix NetScaler ADC** and **NetScaler Gateway**. This is exploitable when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
* **CVE-2025-25249** (CVSS score: 7.3): A heap-based buffer overflow vulnerability in **Fortinet FortiOS**, **FortiSwitchManager**, and **FortiSASE**. This could enable a remote, unauthenticated attacker to execute arbitrary code or commands through specially crafted requests.
### Cisco's Active Exploitation Confirmed
**Cisco** has updated its advisory for **CVE-2026-20079**, confirming active exploitation efforts targeting the flaw since August 2026. The company identified three distinct clusters of post-compromise activity (**UAT-12197**, **UAT-11823**, and **UAT-11988**) on **FMC** instances, where attackers deployed web shells and malware.
This incident follows a recent report by **Sygnia**, which detailed how a China-linked cyber espionage group, **Fire Ant**, has been observed hijacking **Cisco IOS XR** routers. The group uses these devices for persistence, data collection, and to burrow deeper into high-value networks, fundamentally shifting the router's role from a transit device to a collection platform.
### Citrix Flaw Under Attack
**CVE-2026-19490** has also seen significant exploitation activity. **Previdian**'s honeypot systems recorded 56 exploitation attempts since September 3, 2026, with a surge of 36 attempts on September 8, 2026, alone. This highlights the immediate threat posed by this authentication bypass vulnerability.
### Fortinet Vulnerability Leveraged for PivotC2 RAT
The addition of **CVE-2025-25249** to the **KEV** catalog comes after a report from **SOCRadar**. The report detailed a malicious campaign believed to be weaponizing this flaw to deliver **PivotC2**, a sophisticated Node.js remote access trojan (**RAT**). **PivotC2** boasts features such as interactive shells, tunneling, network scanning, and configuration harvesting.
Over 3,000 IP addresses are estimated to have been targeted in this campaign, resulting in 178 compromised devices infected with **PivotC2**, predominantly in the U.S. The activity is attributed to a Russian-speaking threat actor driven by financial gain, with evidence of active exploitation dating back to July 2026.
In the observed attacks, a shell script containing an exploit binary targets vulnerable **FortiGate** instances to establish a reverse shell. This then executes a single-line JavaScript command via **Node.js**, which downloads and decrypts a second-stage JavaScript payload, ultimately delivering **PivotC2**.
**SOCRadar** emphasized that **PivotC2** establishes a persistent outbound TLS connection to a remote command-and-control (**C2**) server. Its comprehensive feature set includes file transfers, SOCKS5/HTTP proxy tunneling, port forwarding, **CIDR**-range scanning, and **FortiGate**-specific configuration harvesting and credential decryption. An auto-mode flag allows for autonomous operations, executing a predefined command sequence upon initial infection.
### Recommendations for Defense
These incidents underscore the critical importance of robust monitoring and timely patching of exposed perimeter edge devices. **SOCRadar** strongly recommends that organizations using **Fortinet** products limit internet access, actively hunt for indicators of compromise, rotate credentials, and apply the latest patches immediately. The constant scanning by threat actors for unpatched vulnerabilities makes these actions paramount for maintaining a strong security posture.