Executive Answer
CISA added three critical vulnerabilities to its Known Exploited Vulnerabilities catalog on September 10, 2026, with a federal patch deadline of September 12. The most severe is a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center — no credentials required, remote access, root-level control. Citrix NetScaler ADC and Gateway carries a CVSS 9.3 auth bypass. Fortinet adds a heap buffer overflow. All three are being actively exploited. Federal agencies must patch by September 12. Private organizations face no legal obligation but run the same exploitable products. The KEV catalog is the US government's public exploitation reality list — treat it as your fastest patch track, regardless of CVSS score.
Key Numbers
- 10.0 CVSS — Severity score for CVE-2026-20079 in Cisco Secure Firewall Management Center. Maximum possible score. Auth bypass, remote, no credentials, root access.
- 9.3 CVSS — Severity score for CVE-2026-19490 in Citrix NetScaler ADC and Gateway. Auth bypass, unauthenticated attacker.
- September 12 — CISA deadline for Federal Civilian Executive Branch agencies to patch all three vulnerabilities.
- 3 — Vendors affected in a single KEV update: Cisco, Citrix, Fortinet. All three are standard enterprise network infrastructure.
- 1,100+ — Total entries in the CISA KEV catalog as of September 2026. Each one represents confirmed active exploitation.
- BOD 22-01 — The Binding Operational Directive that makes KEV patch deadlines legally binding for federal agencies.
Three vendors. Three actively exploited vulnerabilities. One federal deadline that most organizations are watching from the sidelines.
On September 10, 2026, CISA updated its Known Exploited Vulnerabilities catalog with three critical flaws affecting Cisco Secure Firewall Management Center, Citrix NetScaler ADC and Gateway, and Fortinet. Federal agencies have until September 12 to patch. That deadline is two days away from publication of this article.
Private organizations are not subject to the deadline. But the three products are standard enterprise network infrastructure, and the exploits are live.
The Three Vulnerabilities
CVE-2026-20079 — Cisco Secure Firewall Management Center. CVSS 10.0. An unauthenticated remote attacker can exploit an authentication bypass in the Cisco FMC web interface to gain root-level access. No credentials required. No user interaction needed. The FMC is the centralized management console for Cisco Firepower firewalls — the device that controls the rules governing what traffic is permitted or blocked across the entire managed firewall estate. An attacker with root access to the FMC can modify firewall policies, disable security controls, create unauthorized access rules, and gain full visibility into network traffic flows across all managed firewalls. CISA confirmed active exploitation in the wild.
CVE-2026-19490 — Citrix NetScaler ADC and NetScaler Gateway. CVSS 9.3. Authentication bypass allowing an unauthenticated attacker to access the management interface without valid credentials. NetScaler Gateway is widely deployed as the remote access and VPN layer for enterprise environments. Exploitation can allow policy modification, traffic interception, and use of the gateway as a pivot point into the internal network. Citrix products have been a persistent target for nation-state and criminal actors over the past four years — this vulnerability fits a well-established pattern of targeting the network access layer.
CVE-2025-25249 — Fortinet. CVSS 7.3. Heap-based buffer overflow. Fortinet has not disclosed full technical details, consistent with their responsible disclosure process. The lower CVSS score relative to the other two does not change the urgency: CISA's KEV listing confirms active exploitation, and a 7.3 on KEV is more operationally dangerous than a 9.8 that has no known exploit code.
Why the KEV Catalog Changes Patch Prioritization
The standard enterprise patch management model works roughly like this: scan for vulnerabilities, score by CVSS, categorize as critical or high, assign a remediation SLA, track completion. Critical is 30 days. High is 60 days. The higher the CVSS score, the faster the patch.
The problem is that CVSS measures theoretical severity, not exploitation reality. A vulnerability with a CVSS 10.0 that has no public exploit code and no observed exploitation in the wild is not the same threat as a CVSS 7.3 that criminal groups are actively using in ransomware campaigns. CVSS does not capture that distinction. The KEV catalog does.
CISA adds a vulnerability to KEV only when there is credible evidence of active exploitation in the wild — not just proof-of-concept code, not just published advisories, but actual observed attacks. The catalog reflects what attackers are using right now, not what they could theoretically use. That signal is more operationally valuable for prioritization than any CVSS score.
The Fortinet vulnerability in this batch illustrates the point. A CVSS 7.3 under a standard model might be scheduled for the 60-day high-severity track. On KEV, it belongs on your fastest remediation track because someone is actively exploiting it. The score does not tell you that. CISA does.
What Your Patch Program Needs to Change
Subscribe to KEV updates and route them to your vulnerability management team within 24 hours. CISA publishes KEV updates at cisa.gov/known-exploited-vulnerabilities-catalog. The catalog is also available via API for organizations that want to integrate it into their vulnerability management platform. Set up monitoring so that new additions trigger an immediate internal check against your asset inventory — not a weekly scan cycle, not a next-sprint ticket. A same-day impact assessment.
Establish a KEV-specific patch track with a faster SLA than your standard critical vulnerability process. A reasonable target for most organizations is 7 to 14 days for KEV entries. Some environments may need longer based on change management constraints. But your standard 30-day critical SLA is almost certainly too slow for actively exploited vulnerabilities. The attacker is not waiting 30 days.
For this specific batch: prioritize the Cisco FMC first. CVSS 10.0, auth bypass, root access, remote exploitation, no credentials — Cisco FMC access gives an attacker control over your entire managed firewall policy. If you run Cisco Firepower managed through FMC, this is your highest-priority remediation this week. Check for vendor patches and apply them. If no patch is yet available, restrict FMC management interface access to specific administrative source IPs and verify that internet-facing exposure is eliminated.
Check your Citrix NetScaler exposure. The NetScaler Gateway auth bypass continues a pattern of Citrix edge device targeting that has produced significant breaches over the past several years. If you run NetScaler Gateway as your remote access layer, confirm your patch status and verify that the management interface is not internet-exposed. Citrix patch advisories are published at support.citrix.com.
Asaf's Take
The KEV catalog is one of the most underutilized resources in enterprise vulnerability management. Organizations that built their patch programs around CVSS scoring are making prioritization decisions based on theoretical severity. CISA is telling them what is being used in actual attacks, right now, for free. The gap between organizations that act on KEV within days and those that route it through their standard 30-day critical track is not a resources gap — it is a prioritization philosophy gap. When you see a CVSS 10.0 Cisco FMC auth bypass on KEV, you are looking at the highest-risk category of vulnerability that exists: maximum severity, confirmed exploitation, centralized management plane access. That should not go into a 30-day queue. It should go to the top of this week's patch list, with compensating controls applied today if the patch is not yet available. The Fortinet entry is the one worth watching closely. A CVSS 7.3 that makes the KEV catalog often turns out to be more operationally dangerous than the headline numbers suggest — because attackers chose it for a reason, and that reason usually becomes clear in the post-incident reports filed six months later.
Related Reading
Does your patch management program treat KEV entries differently from other critical vulnerabilities?
Let's Review Your Vulnerability Management ProcessSources
- CISA Known Exploited Vulnerabilities Catalog, September 10, 2026 update: cisa.gov/known-exploited-vulnerabilities-catalog
- CISA Binding Operational Directive 22-01: cisa.gov/binding-operational-directive-22-01
- Cisco Security Advisory: CVE-2026-20079 Cisco Secure Firewall Management Center (September 2026)
- Citrix Security Bulletin: CVE-2026-19490 NetScaler ADC and Gateway (September 2026)
- Fortinet PSIRT Advisory: CVE-2025-25249 (September 2026)
- BleepingComputer: "CISA Flags Cisco, Citrix, Fortinet Flaws as Actively Exploited" (September 10, 2026)