CISA gives agencies until Saturday to patch three exploited flaws

Three exploited networking flaws now carry a three-day federal patch deadline.

CSBadmin
2 Min Read

Federal civilian agencies have three days to close three networking flaws that attackers are already exploiting. The Cybersecurity and Infrastructure Security Agency added all three to its Known Exploited Vulnerabilities catalog on Wednesday, setting a September 12 deadline under binding operational directive 26-04.

If you run Cisco Secure Firewall Management Center, patch it first. CVE-2026-20079 carries a CVSS score of 10.0, and a stranger who reaches the web interface can run script files and land root without any credential. Cisco’s own testing found the bug, and the company now says attackers exploited it during August. Talos traced three intrusions. One dropped a web shell into the Tomcat webroot. Another, linked to Russia’s Sandworm, swaps in a doctored license file to open a reverse shell, then lifts firewall configurations. A third, tied to Qilin ransomware, signs in with static credentials from CVE-2026-20316.

Citrix NetScaler is the second entry. Its CVE-2026-19490, scored 9.3, lets an attacker sidestep authentication on ADC and Gateway appliances set up as a gateway or AAA virtual server. Honeypots at Previdian have logged 56 attempts since September 3, and 36 landed on a single day, September 8.

The third, CVE-2025-25249, is a heap overflow in Fortinet FortiOS, FortiSwitchManager and FortiSASE. SOCRadar tied it to PivotC2, a Node.js remote access trojan, saying attackers hit more than 30,000 IP addresses and infected 178 devices, mostly in the US. Patches shipped in January.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.