ISA Adds Exploited Cisco, Citrix and Fortinet Flaws to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added actively exploited vulnerabilities affecting Cisco, Citrix and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog.

The agency's latest additions highlight continuing attacks against internet-facing network and remote-access technologies, which remain attractive entry points for threat actors seeking initial access to enterprise environments.
U.S. federal civilian agencies have been given a remediation deadline of September 12, 2026, requiring affected systems to be patched or otherwise addressed within the specified timeframe.
The development is particularly important for organizations operating perimeter security appliances, VPN infrastructure and externally accessible enterprise services, as successful exploitation of these technologies can provide attackers with a direct path into protected networks.
CISA's Known Exploited Vulnerabilities Catalog
CISA maintains the KEV catalog to track vulnerabilities for which there is evidence of exploitation in real-world attacks.
Unlike vulnerabilities that are merely rated as critical or assigned a high CVSS score, inclusion in the KEV catalog indicates that defenders should treat the flaw as an active operational threat.
Federal Civilian Executive Branch agencies are required to remediate KEV-listed vulnerabilities according to the deadlines specified in CISA's Binding Operational Directive framework.
The latest additions involving Cisco, Citrix and Fortinet reinforce the importance of prioritizing vulnerabilities based on observed exploitation rather than severity scores alone.
Cisco, Citrix and Fortinet Under the Spotlight
The newly highlighted vulnerabilities affect products commonly deployed at the network perimeter.
These technologies are particularly attractive to attackers because they frequently provide connectivity between the public internet and internal corporate environments.
A successful compromise can potentially allow threat actors to:
- Gain initial access to enterprise networks
- Steal authentication information
- Establish persistent access
- Deploy malware
- Move laterally between systems
- Intercept sensitive traffic
- Target additional network infrastructure
Organizations should therefore prioritize internet-facing systems when conducting remediation.
Why Network Appliances Are High-Value Targets
Network security appliances often operate with elevated privileges and have extensive visibility into internal infrastructure.
Unlike a compromised workstation, an attacker controlling a VPN gateway, firewall or remote-access appliance may gain a strategically valuable position from which to monitor or manipulate network traffic.
Threat actors have repeatedly targeted vulnerabilities in products such as:
- VPN gateways
- Firewalls
- Secure web gateways
- Network management systems
- Remote-access platforms
- Application delivery controllers
CISA and its partner agencies have previously warned that vulnerabilities in internet-facing networking equipment are routinely exploited by both financially motivated criminals and state-sponsored groups.
Citrix Vulnerabilities Remain a Persistent Risk
Citrix NetScaler products have historically been heavily targeted because they are commonly exposed to the internet and can provide access to enterprise applications.
Previous Citrix vulnerabilities, including CVE-2023-4966, known as Citrix Bleed, have been exploited by ransomware groups and other threat actors.
CISA has previously documented exploitation of Citrix vulnerabilities as part of broader campaigns targeting externally accessible infrastructure.
The continued appearance of Citrix vulnerabilities in active-exploitation warnings demonstrates why organizations should not assume that previously patched appliances remain secure simply because they have not generated obvious security alerts.
Fortinet Devices Continue to Attract Attackers
Fortinet's FortiGate and related security appliances have also repeatedly appeared in threat intelligence reports involving exploitation of internet-facing infrastructure.
One well-known example is CVE-2018-13379, a FortiOS SSL VPN path-traversal vulnerability that allowed unauthenticated attackers to retrieve sensitive system files.
CISA and international cybersecurity agencies have previously documented threat actors exploiting Fortinet vulnerabilities to gain initial access to targeted networks.
The continued targeting of Fortinet products illustrates a broader problem: vulnerabilities in perimeter devices can remain exploitable long after their initial disclosure if organizations fail to patch every exposed appliance.
Cisco Infrastructure Also Remains a Major Target
Cisco networking products represent another high-value target because they are widely deployed across enterprise and government environments.
Attackers have historically exploited vulnerabilities affecting Cisco security and networking technologies to gain unauthorized access or establish persistence.
CISA's KEV approach is particularly important for these products because organizations may operate large numbers of geographically distributed Cisco devices, making comprehensive patch verification difficult.
Security teams should maintain an accurate inventory of:
- Cisco firewalls
- VPN appliances
- Routers
- Switches
- Network management platforms
- Internet-facing administrative interfaces
September 12 Federal Deadline
For affected U.S. federal civilian agencies, September 12, 2026 represents the remediation deadline associated with the latest CISA action.
Federal agencies are expected to identify affected systems and take appropriate remediation measures within the required timeframe.
Although the KEV deadline directly applies to U.S. federal civilian agencies, private-sector organizations can also use the same deadline as a useful benchmark for prioritizing their own remediation efforts.
Organizations operating affected products should not wait until the deadline to begin remediation.
What Security Teams Should Do
Security teams should begin by identifying every internet-facing instance of the affected Cisco, Citrix and Fortinet products.
1. Identify Exposed Assets
Review:
- Internet-facing IP addresses
- VPN gateways
- Firewalls
- Remote-access systems
- Citrix infrastructure
- Network appliances
- Cloud-hosted appliances
- Disaster-recovery environments
Asset discovery should include systems that may not appear in the organization's primary configuration-management database.
2. Verify Software Versions
Determine the exact firmware or software version running on each affected device.
Do not assume that a device is protected simply because it received a general maintenance update.
Verify the installed version against the vendor's security advisory.
3. Apply Vendor Security Updates
Where patches are available, organizations should apply the relevant security updates as soon as operationally possible.
For systems that cannot immediately be patched, administrators should implement the vendor-recommended mitigations and restrict exposure where feasible.
4. Restrict Internet Exposure
Where direct public access is not required, organizations should consider:
- Removing unnecessary internet exposure
- Restricting management interfaces
- Applying access-control lists
- Limiting administrative access through VPN
- Using dedicated management networks
- Implementing IP allowlisting
5. Review Authentication Logs
Because network appliances can serve as initial-access points, security teams should review authentication activity for signs of compromise.
Look for:
- Unexpected VPN logins
- Unknown administrator accounts
- Unusual geographic locations
- Impossible-travel events
- Multiple failed authentication attempts
- Unexpected configuration changes
- New certificates
- Unknown sessions
Patch Management Is Not Enough
Applying a patch is essential, but organizations should not automatically assume that a previously vulnerable system is clean after remediation.
If attackers exploited a vulnerability before the patch was installed, they may have already:
- Created accounts
- Installed web shells
- Modified configurations
- Stolen credentials
- Added persistence mechanisms
- Deployed malware
- Established alternate access paths
Security teams should therefore combine vulnerability remediation with compromise assessment.
Recommended Threat-Hunting Activities
Following remediation, defenders should investigate the affected systems for suspicious activity.
Threat hunting should include:
Authentication analysis
Look for unexpected administrative logins and unusual VPN sessions.
Configuration review
Compare current configurations against known-good baselines.
Account investigation
Identify newly created or modified privileged accounts.
Network monitoring
Search for unexpected outbound connections from security appliances.
Persistence checks
Look for unauthorized scripts, scheduled jobs, certificates or configuration changes.
Credential exposure
Assume credentials stored or processed by a compromised appliance may have been exposed and rotate them where appropriate.
Why CISA's Warning Matters
The most important part of CISA's latest announcement is not necessarily the severity rating assigned to an individual vulnerability.
It is the evidence that the vulnerabilities are being exploited in real-world attacks.
Historical CISA guidance shows that threat actors frequently exploit weaknesses in internet-facing infrastructure to obtain initial access. Once inside a network, attackers can use legitimate credentials, remote-access tools and native system utilities to move further into the environment.
This makes perimeter vulnerabilities particularly dangerous for organizations that operate:
- Hybrid cloud environments
- Remote-access infrastructure
- Critical infrastructure
- Financial systems
- Government networks
- Healthcare environments
- Large enterprise networks
Organizations Outside the U.S. Should Also Act
Although the September 12 deadline applies to U.S. federal requirements, organizations worldwide should not treat the announcement as a U.S.-only concern.
Cisco, Citrix and Fortinet technologies are deployed globally.
Attackers do not restrict exploitation campaigns based on an organization's geographic location.
Organizations in other countries should therefore use the KEV additions as an additional risk signal and evaluate whether their own environments contain the affected products.
Broader Security Lesson
The latest CISA action reinforces an increasingly important vulnerability-management principle:
Prioritize exploitation status, not just CVSS severity.
A vulnerability with a lower theoretical severity but confirmed exploitation can represent a greater immediate operational risk than a critical vulnerability that has never been observed being abused.
CISA's KEV catalog provides security teams with a practical way to identify vulnerabilities where remediation should receive urgent attention.
Conclusion
CISA's latest KEV additions involving Cisco, Citrix and Fortinet highlight the continuing threat posed by vulnerabilities in internet-facing enterprise infrastructure.
For U.S. federal civilian agencies, the affected systems face a September 12, 2026 remediation deadline.
For private-sector and international organizations, the warning should serve as an immediate trigger to review exposed network infrastructure, verify software versions, apply available security updates and investigate systems for signs of previous compromise.
Network appliances remain some of the most valuable assets for attackers because they sit directly at the boundary between the internet and internal networks.
A vulnerable firewall, VPN gateway or application-delivery appliance can therefore become much more than another unpatched system—it can become the attacker's front door into the enterprise.
Security teams should treat CISA KEV additions as actionable intelligence and prioritize remediation accordingly.
Related reporting
Hackers Exploit Critical WSO2 API Manager JWT Flaw Using Forged Admin Tokens
Security researchers have detected active exploitation attempts targeting a critical authentication-bypass vulnerability in WSO2 API Manager, with attackers sending forged JSON Web Tokens (JWTs) containing administrator privileges.
Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Code Feature
Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could allow a nearby attacker to execute unauthorized code or access information stored on the console.
China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE Backdoor
China-linked threat actors have been observed chaining multiple vulnerabilities in Google Chrome and Microsoft Windows as part of sophisticated cyber-espionage campaigns targeting non-governmental organizations and other high-value organizations.


