CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

Summary

CISA has added three vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities catalog. Federal agencies are mandated to patch these flaws by September 12, 2026.

IFF Assessment

FOE

The inclusion of actively exploited vulnerabilities in critical infrastructure products indicates an increased threat landscape for defenders.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.

Defender Context

Defenders need to be aware of actively exploited vulnerabilities in widely used network devices from vendors like Cisco, Citrix, and Fortinet. Prompt patching is crucial to mitigate the risk of these critical flaws being leveraged in attacks against federal agencies and potentially other organizations.

Read Full Story →