CISA Mandates Patches for Critical Cisco, Citrix, and Fortinet Vulnerabilities by September 12
CISA added three actively exploited vulnerabilities in Cisco, Citrix, and Fortinet products to its KEV catalog, requiring federal agencies to apply patches by September 12, 2026. The flaws enable remote code execution and authentication bypasses, with reported exploitation attempts targeting critical infrastructure and enterprise networks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
The vulnerabilities are listed below -
CVE-2026-20079 (CVSS score: 10.0) - An authentication
*** END OF TRANSMISSION ***