Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline




The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged three exploited flaws in Cisco, Citrix, and Fortinet, prompting a federal patch deadline of September 12, 2026, for Federal Civilian Executive Branch (FCEB) agencies. These vulnerabilities have witnessed active exploitation efforts, with threat actors taking advantage of their lack of robust monitoring or telemetry logging. Organizations are urged to take immediate action to address these vulnerabilities and apply the necessary patches to prevent exploitation.



  • CISA has flagged three exploited flaws in Cisco, Citrix, and Fortinet, prompting a federal patch deadline of September 12, 2026, for Federal Civilian Executive Branch (FCEB) agencies.
  • The vulnerabilities are CVE-2026-20079, CVE-2026-19490, and CVE-2025-25249, each with a corresponding CVSS score highlighting their severity.
  • Cisco, Citrix, and Fortinet have witnessed active exploitation efforts, with exploitation activity recorded since September 3, 2026.
  • A malicious attack campaign, suspected to be the work of a Russian-speaking threat actor, has been linked to CVE-2025-25249, delivering a feature-rich Node.js remote access trojan (RAT) codenamed PivotC2.
  • PivotC2 establishes a persistent outbound TLS connection to a remote command-and-control (C2) server, featuring a range of capabilities, including interactive shells and file transfers.
  • Organizations are urged to limit internet access, hunt for indicators of compromise, rotate credentials, and apply the latest patches to mitigate the risk of exploitation.
  • Priority should be given to robust monitoring and telemetry logging for perimeter edge devices to prevent initial access by threat actors.



  • The cybersecurity landscape has witnessed a plethora of vulnerabilities and exploits in recent times, with various organizations and individuals falling prey to these threats. In a recent development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged three exploited flaws in Cisco, Citrix, and Fortinet, prompting a federal patch deadline of September 12, 2026, for Federal Civilian Executive Branch (FCEB) agencies.

    The vulnerabilities in question are CVE-2026-20079, CVE-2026-19490, and CVE-2025-25249, each with a corresponding CVSS score that highlights the severity of the issues. CVE-2026-20079 is an authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software, allowing an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device, thereby obtaining root access to the underlying operating system. This vulnerability has witnessed active exploitation efforts, with Cisco updating its advisory to note that it became aware of these efforts in August 2026.

    CVE-2026-19490 is an authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy). This vulnerability has also witnessed exploitation activity, with a total of 56 attempts recorded since September 3, 2026, with 36 attempts recorded on September 8, 2026, alone.

    CVE-2025-25249 is a heap-based buffer overflow vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE, which could allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. This vulnerability has been associated with a malicious attack campaign suspected to have weaponized the flaw to deliver a feature-rich Node.js remote access trojan (RAT) codenamed PivotC2.

    The attack campaign, suspected to be the work of a Russian-speaking threat actor driven by financial gain, involved the use of a shell script containing an exploit binary that targets a vulnerable FortiGate instance to establish a reverse shell and run a single-line JavaScript command via Node.js. This, in turn, leads to the download of a second-stage JavaScript payload, which is decrypted and executed to deliver PivotC2.

    PivotC2 establishes a persistent outbound TLS connection to a remote command-and-control (C2) server, featuring a range of capabilities, including interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, local and remote port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption. The feature set includes an auto-mode flag that enables autonomous operations, automatically running a predefined command sequence upon initial infection.

    The findings highlight the importance of robust monitoring and telemetry logging for perimeter edge devices, as threat actors continuously scan exposed devices to obtain initial access. SOCRadar is recommending organizations using Fortinet products to limit internet access, hunt for indicators of compromise, rotate credentials, and apply the latest patches.

    This incident serves as a stark reminder of the importance of prioritizing cybersecurity measures and staying vigilant in the face of emerging threats. The vulnerabilities highlighted by CISA underscore the need for organizations to keep pace with the rapidly evolving cybersecurity landscape, applying patches and updates in a timely manner to mitigate the risk of exploitation.

    In recent times, Cisco routers have been a prime target for cyber attackers, with a report from Sygnia noting the observation of a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrowing deeper into high-value networks via custom malware.

    The addition of CVE-2025-25249 to the Known Exploited Vulnerabilities (KEV) catalog follows a report from SOCRadar about a malicious attack campaign suspected to have weaponized the flaw to deliver a feature-rich Node.js remote access trojan (RAT) codenamed PivotC2. The post-exploitation framework supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.

    The estimated 3,000 IP addresses targeted as part of the campaign resulted in the infection of 178 devices with PivotC2, with the majority of the compromises concentrated in the U.S. The activity is assessed to be the work of a Russian-speaking threat actor driven by financial gain, with the earliest evidence of active exploitation dating back to July 2026.

    The security community is urging organizations to take immediate action to address these vulnerabilities and apply the necessary patches to prevent exploitation. With the federal patch deadline of September 12, 2026, for FCEB agencies, this serves as a critical reminder of the importance of prioritizing cybersecurity measures and staying vigilant in the face of emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISA-Flags-Exploited-Cisco-Citrix-Fortinet-Flaws-Sets-Sept-12-Federal-Patch-Deadline-ehn.shtml

  • https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-20079

  • https://www.cvedetails.com/cve/CVE-2026-20079/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19490

  • https://www.cvedetails.com/cve/CVE-2026-19490/

  • https://nvd.nist.gov/vuln/detail/CVE-2025-25249

  • https://www.cvedetails.com/cve/CVE-2025-25249/


  • Published: Thu Sep 10 08:02:11 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us