CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Summary
CISA has added three vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities catalog. Federal agencies are mandated to patch these flaws by September 12, 2026.
IFF Assessment
The inclusion of actively exploited vulnerabilities in critical infrastructure products indicates an increased threat landscape for defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.
Defender Context
Defenders need to be aware of actively exploited vulnerabilities in widely used network devices from vendors like Cisco, Citrix, and Fortinet. Prompt patching is crucial to mitigate the risk of these critical flaws being leveraged in attacks against federal agencies and potentially other organizations.