Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiSwitchManager, an authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway, and an out-of-bounds write vulnerability in Google Chromium V8. These vulnerabilities highlight the growing concerns over the increasing sophistication and exploitation of vulnerabilities in the digital landscape, and it is essential for organizations to address these vulnerabilities as soon as possible to protect their networks against attacks exploiting these flaws.
Four new vulnerabilities have been added to the Known Exploited Vulnerabilities (KEV) catalog, highlighting growing concerns over increasing vulnerability exploitation. CVE-2025-25249: Heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiSwitchManager, being actively exploited in the wild. CVE-2026-19490: Authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway, allowing unauthenticated remote attackers to bypass authentication. CVE-2026-87491: Out-of-bounds write vulnerability in Google Chromium V8, allowing arbitrary code execution. CVE-2026-20079: Authentication bypass vulnerability in Cisco Secure FMC’s web interface, allowing unauthenticated remote attackers to bypass authentication.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the growing concerns over the increasing sophistication and exploitation of vulnerabilities in the digital landscape. The vulnerabilities added to the catalog are CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, and CVE-2026-20079.
The first vulnerability, CVE-2025-25249, is a heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiSwitchManager. This vulnerability allows unauthenticated remote attackers to execute arbitrary code or commands by sending specially crafted packets. The vulnerability is being actively exploited in the wild, including in attacks that deployed the PivotC2 remote access trojan on compromised FortiGate devices.
The second vulnerability, CVE-2026-19490, is an authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway. This vulnerability allows unauthenticated remote attackers to bypass authentication through the SAML HTTP-Redirect binding, potentially gaining unauthorized access to protected services.
The third vulnerability, CVE-2026-87491, is an out-of-bounds write vulnerability in Google Chromium V8. This vulnerability affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine. An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox. Google fixed the issue in Chrome 153.0.8010.36 and later versions.
The fourth vulnerability, CVE-2026-20079, is an authentication bypass vulnerability in Cisco Secure FMC’s web interface. This vulnerability allows unauthenticated remote attackers to bypass authentication and send crafted HTTP requests to execute scripts, potentially gaining root access to the underlying operating system.
These vulnerabilities highlight the growing concerns over the increasing sophistication and exploitation of vulnerabilities in the digital landscape. According to CISA, these vulnerabilities have been identified as being actively exploited in the wild, and it is essential for organizations to address these vulnerabilities as soon as possible to protect their networks against attacks exploiting these flaws.
The CISA has issued a statement urging federal agencies to address the vulnerabilities by the due dates mentioned, with Windows flaws needing to be fixed by September 22, 2026, and the remaining vulnerabilities needing to be addressed by September 12, 2026.
The addition of these vulnerabilities to the KEV catalog also highlights the growing concern over the security of AI systems. The vulnerability in Google Chromium V8, CVE-2026-87491, is the seventh actively exploited Chrome zero-day of 2026, and it has been identified as a critical vulnerability that can be exploited through a specially crafted HTML page.
The vulnerability in Citrix NetScaler, CVE-2026-19490, also highlights the growing concern over the security of cloud-based services. This vulnerability allows unauthenticated remote attackers to bypass authentication through the SAML HTTP-Redirect binding, potentially gaining unauthorized access to protected services.
The vulnerabilities added to the KEV catalog also highlight the importance of implementing robust security measures to protect networks against attacks exploiting these flaws. The CISA has emphasized the importance of keeping software up-to-date and applying security patches as soon as possible to prevent exploitation of these vulnerabilities.
In conclusion, the addition of these vulnerabilities to the KEV catalog highlights the growing concerns over the increasing sophistication and exploitation of vulnerabilities in the digital landscape. It is essential for organizations to address these vulnerabilities as soon as possible to protect their networks against attacks exploiting these flaws.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-Vulnerabilities-to-Known-Exploited-Vulnerabilities-Catalog-Highlighting-Growing-Concerns-Over-AI-Security-ehn.shtml
https://securityaffairs.com/198850/security/u-s-cisa-adds-cisco-google-chromium-v8-fortinet-and-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2025-25249
https://www.cvedetails.com/cve/CVE-2025-25249/
https://nvd.nist.gov/vuln/detail/CVE-2026-19490
https://www.cvedetails.com/cve/CVE-2026-19490/
https://nvd.nist.gov/vuln/detail/CVE-2026-87491
https://www.cvedetails.com/cve/CVE-2026-87491/
https://nvd.nist.gov/vuln/detail/CVE-2026-20079
https://www.cvedetails.com/cve/CVE-2026-20079/
Published: Thu Sep 10 16:30:19 2026 by llama3.2 3B Q4_K_M