Threat Advisory

CISA Adds Four Known Exploited Vulnerabilities to Catalog

HIGH September 9, 2026

What happened

The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities are actively exploited, indicating they are being used by malicious actors to compromise affected systems. The vulnerabilities include a heap-based buffer overflow in Fortinet products, an authentication bypass in Citrix NetScaler, an out-of-bounds write in Google Chromium V8, and an authentication bypass in Cisco Firewall Management Center. These flaws impact widely used enterprise products and are associated with severe risks related to asset control and data security. The vulnerabilities are classified as high severity due to ongoing exploitation and the critical nature of the affected components. The addition to the KEV Catalog underscores the importance for organisations to prioritise remediation efforts to close these security gaps swiftly.

Who is affected

Organisations running affected deployments of Fortinet multiple products, Citrix NetScaler, Google Chromium, and Cisco Firewall Management Center are impacted by these vulnerabilities. Due to the prevalence of these products in enterprise environments, a broad range of organisations could be exposed to the associated risks. The vulnerabilities affect systems that are reachable from the internet and could be exploited through specific attack vectors, risking control of affected assets and potential data breaches.

Recommended actions

  1. Verify whether affected products are exposed on publicly accessible networks.
  2. Implement rapid remediation strategies in accordance with organisational vulnerability management policies, prioritising the vulnerabilities listed in the KEV Catalog.
  3. Ensure active monitoring of affected systems for signs of compromise, especially for systems that may have been targeted for exploitation.

Indicators of compromise

Indicators are not currently available for these vulnerabilities.

Affected

Vendors: Cisco, Citrix, Fortinet, Google

Products: Multiple Products, NetScaler, Chromium V8, Firewall Management Center

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

Severityhigh
CVECVE-2025-25249, CVE-2026-19490, CVE-2026-87491, CVE-2026-20079
PublishedSeptember 9, 2026
VendorCisco, Citrix, Fortinet, Google
ProductsMultiple Products, NetScaler, Chromium V8, Firewall Management Center

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent