U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini September 10, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
  • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
  • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
  • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability 

CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure FMC’s web interface and lets unauthenticated remote attackers bypass authentication and send crafted HTTP requests to execute scripts, potentially gaining root access to the underlying operating system.

CVE-2026-87491 (CVSS score of 8.8) CVE-2026-87491 is the seventh actively exploited Chrome zero-day of 2026. The bug affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine. An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153.0.8010.36 and later versions.

 “Google is aware that an exploit for CVE-2026-87491 exists in the wild.” reads the advisory.

CVE-2025-25249 (CVSS score of 8.1) is a heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiSwitchManager. The flaw resides in the cw_acd daemon and allows unauthenticated remote attackers to execute arbitrary code or commands by sending specially crafted packets. The vulnerability is being actively exploited in the wild, including in attacks that deployed the PivotC2 remote access trojan on compromised FortiGate devices.

CVE-2026-19490 (CVSS score of 9.3) is an authentication bypass vulnerability. The flaw affects Citrix NetScaler ADC and NetScaler Gateway and allows unauthenticated remote attackers to bypass authentication through the SAML HTTP-Redirect binding, potentially gaining unauthorized access to protected services. The vulnerability has been added to CISA’s Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the Windows flaws by September 22, 2026, while the remaining must be addressed by September 12, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



you might also like

leave a comment