Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump absent as New York marks 25 years since 9/11 with first Muslim mayor

    September 11, 2026

    Reform UK beset by internal row over response to Dover and Portsmouth protests | Reform UK

    September 11, 2026

    Thrive Capital led VCs into pro sports ownership; Collaborative Fund just upped that play

    September 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump absent as New York marks 25 years since 9/11 with first Muslim mayor
    • Reform UK beset by internal row over response to Dover and Portsmouth protests | Reform UK
    • Thrive Capital led VCs into pro sports ownership; Collaborative Fund just upped that play
    • CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
    • Bitcoin mining supplies 90% of HIVE’s $1 million daily revenue despite ongoing AI expansion
    • Your partner’s snoring could be impacting your health
    • How Oneil Cruz Walked Away From Deadly Crash With a Fixer’s Help — ProPublica
    • Did Trump threaten to turn off Niagara Falls water unless Canada pays tariff?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 11, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 10, 2026Vulnerability / Network Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.

    The vulnerabilities are listed below –

    • CVE-2026-20079 (CVSS score: 10.0) – An authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
    • CVE-2026-19490 (CVSS score: 9.3) – An authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
    • CVE-2025-25249 (CVSS score: 7.3) – A heap-based buffer overflow vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that could allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

    The development comes as Cisco updated its advisory for CVE-2026-20079 to note that it became aware of active exploitation efforts targeting the flaw in August 2026. It did not disclose any additional details.

    Cybersecurity

    Cisco routers have been an attack magnet in recent years. In a report published late last month, Sygnia said it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.

    “This behavior shifts the router’s role from a transit device to a collection platform,” the cybersecurity company noted. “Once the actor controlled the router, the device became a vantage point for observing traffic moving through trusted network paths.”

    CVE-2026-19490, on the other hand, has witnessed exploitation activity targeting Previdian’s honeypot systems, with a total of 56 attempts registered since September 3, 2026. Of these, 36 attempts were recorded on September 8, 2026, alone.

    The addition of CVE-2025-25249 to the KEV catalog follows a report from SOCRadar about a malicious attack campaign that’s suspected to have weaponized the flaw to deliver a feature-rich Node.js remote access trojan (RAT) codenamed PivotC2. The post-exploitation framework supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.

    More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2. The majority of the compromises are concentrated in the U.S. The activity is assessed to be the work of a Russian-speaking threat actor driven by financial gain. The earliest evidence of active exploitation of the flaw dates back to July 2026.

    Cybersecurity

    In the observed attacks, a shell script containing an exploit binary targets a vulnerable FortiGate instance to establish a reverse shell and run a single-line JavaScript command via Node.js. This, in turn, leads to the download of a second-stage JavaScript payload, which is decrypted and executed to deliver PivotC2.

    “PivotC2 establishes a persistent outbound TLS connection to a remote command-and-control (C2) server. Its feature set includes interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, local and remote port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption,” SOCRadar said. “An auto-mode flag enables autonomous operations, automatically running a predefined command sequence upon initial infection.”

    The findings once again demonstrate that threat actors are continuously scanning exposed perimeter edge devices to obtain initial access by taking advantage of their lack of robust monitoring or telemetry logging. SOCRadar is recommending organizations using Fortinet products to limit internet access, hunt for indicators of compromise, rotate credentials, and apply the latest patches.

    CISA Cisco Citrix deadline Exploited Federal flags flaws Fortinet patch Sept Sets
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

    PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

    New Android malware encrypts files, steals data, and harasses victims

    Critical NetScaler Vulnerability Exploited in Attacks

    Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

    Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump absent as New York marks 25 years since 9/11 with first Muslim mayor

    September 11, 2026

    Reform UK beset by internal row over response to Dover and Portsmouth protests | Reform UK

    September 11, 2026

    Thrive Capital led VCs into pro sports ownership; Collaborative Fund just upped that play

    September 11, 2026

    CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    September 11, 2026
    Latest Posts

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump absent as New York marks 25 years since 9/11 with first Muslim mayor

    September 11, 2026

    Reform UK beset by internal row over response to Dover and Portsmouth protests | Reform UK

    September 11, 2026

    Thrive Capital led VCs into pro sports ownership; Collaborative Fund just upped that play

    September 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.