news.mlab.sh
Back to the feed
vulnerability

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

CriticalCVSS 10.0
Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities – one in Cisco Secure Firewall Management Center, one in Citrix NetScaler, and one in Fortinet FortiOS – requiring Federal Civilian Executive Branch agencies to patch by September 12, 2026. These vulnerabilities are being actively leveraged, with evidence of exploitation dating back to August 2026, and a Chinese-nexus cyber espionage group, Fire Ant, has been utilizing Cisco routers for data collection and persistence. A separate campaign, linked to a Russian-speaking threat actor, has weaponized a Fortinet vulnerability to deliver a Node.js remote access trojan (PivotC2).

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities – one in Cisco Secure Firewall Management Center (FMC) Software, one in Citrix NetScaler ADC and NetScaler Gateway, and one in Fortinet FortiOS – to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. These vulnerabilities are being actively leveraged, with evidence of exploitation dating back to August 2026.

CVE-2026-20079 (CVSS score: 10.0) is an authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software, allowing an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. Cisco routers have been an attack magnet in recent years, with a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.

CVE-2026-19490 (CVSS score: 9.3) has witnessed exploitation activity targeting Previdian’s honeypot systems, with a total of 56 attempts registered since September 3, 2026. Of these, 36 attempts were recorded on September 8, 2026, alone.

CVE-2025-25249 (CVSS score: 7.3) is a heap-based buffer overflow vulnerability in FortiOS, FortiSwitchManager, and FortiSASE that could allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. The addition of CVE-2025-25249 to the KEV catalog follows a report from SOCRadar about a malicious attack campaign that’s suspected to have weaponized the flaw to deliver a feature-rich Node.js remote access trojan (RAT) codenamed PivotC2. The post-exploitation framework supports features such as interactive shells, tunneling, network scanning, and configuration harvesting. More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2. The majority of the compromises are concentrated in the U.S. The activity is assessed to be the work of a Russian-speaking threat actor driven by financial gain.

In the observed attacks, a shell script containing an exploit binary targets a vulnerable FortiGate instance to establish a reverse shell and run a single-line JavaScript command via Node.js. This, in turn, leads to the download of a second-stage JavaScript payload, which is decrypted and executed to deliver PivotC2. “PivotC2 establishes a persistent outbound TLS connection to a remote command-and-control (C2) server. Its feature set includes interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, local and remote port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption,” SOCRadar said. “An auto-mode flag enables autonomous operations, automatically running a predefined command sequence upon initial infection.”

The findings once again demonstrate that threat actors are continuously scanning exposed perimeter edge devices to obtain initial access by taking advantage of their lack of robust monitoring or telemetry logging. SOCRadar is recommending organizations using Fortinet products to limit internet access, hunt for indicators of compromise, rotate credentials, and apply the latest patches.

Read the full article at The Hacker News