VORANT. Threat Intelligence Sign in Get the full feed

CISA adds Fortinet, Citrix, Chromium, Cisco flaws to KEV

severe vulnerability government-nationaltechnologyinfrastructure

CISA added four actively exploited vulnerabilities in Fortinet, Citrix NetScaler, Chromium V8, and Cisco Firewall Management Center to its KEV catalog.

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed evidence of active exploitation. The affected products span network security appliances and browser engines widely deployed across enterprise and federal environments: a heap-based buffer overflow in multiple Fortinet products (CVE-2025-25249), an authentication bypass using an alternate path or channel in Citrix NetScaler (CVE-2026-19490), an out-of-bounds write in Google Chromium's V8 engine (CVE-2026-87491), and an authentication bypass using an alternate path or channel in Cisco Firewall Management Center (CVE-2026-20079).

Authentication bypass vulnerabilities in NetScaler and Cisco FMC are particularly concerning for defenders because they affect perimeter/management infrastructure that is frequently internet-exposed and, if compromised, can grant attackers broad control over network security controls. The Fortinet heap overflow and Chromium V8 out-of-bounds write are memory-corruption classes commonly leveraged for remote code execution or sandbox escape.

Under Binding Operational Directive (BOD) 26-04, FCEB agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation, and must check for prior compromise before patching. While BOD 26-04 is mandatory only for federal agencies, CISA urges all organizations running Fortinet, Citrix NetScaler, Cisco Firewall Management Center, or Chromium-based browsers to patch immediately and review logs for signs of prior exploitation given active in-the-wild attacks.

Mentioned in this report

Vulnerabilities CVE-2025-25249KEVCVE-2026-19490KEVCVE-2026-20079KEVCVE-2026-87491KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free