CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today
CISA's September 12 deadline covers confirmed exploited flaws in Cisco FMC, Citrix NetScaler, and Fortinet FortiOS. Federal agencies must patch by tomorrow; everyone else should be moving too.

CISA’s Known Exploited Vulnerabilities catalog carries a September 12 federal remediation deadline for three confirmed exploited flaws across Cisco, Citrix, and Fortinet products. That is tomorrow. Here is what to patch and in what order.
Priority one: Cisco FMC CVE-2026-20079 (CVSS 10.0)
CVE-2026-20079 is an authentication bypass in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can bypass authentication and execute scripts on the underlying operating system with root privileges. CISA added it to KEV on September 9.
This is the management plane for Cisco Secure Firewall deployments. Root on FMC means access to every policy, rule, and traffic log the device administers. CVSS 10.0 is not a rounding error here: no credentials, no user interaction, network reachable, full OS compromise.
Cisco Talos subsequently reported that three separate threat clusters are exploiting this flaw, including actors tied to ransomware operations and state-sponsored activity. This is not a theoretical threat.
Patch path: Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2. If patching takes time, restrict FMC management interface access to trusted hosts on a dedicated management VLAN. That reduces the attack surface; it does not close the vulnerability. Full coverage.
Priority two: Citrix NetScaler CVE-2026-19490 (CVSS 9.3)
CVE-2026-19490 is an unauthenticated authentication bypass in Citrix NetScaler ADC and NetScaler Gateway. CISA added it to KEV on September 9, the same batch as Cisco. The September 12 deadline applies.
Citrix patched this August 19. Active exploitation was confirmed September 5 by Previdian. The flaw has been in the wild for at least six days, and CISA’s catalog entry confirms the exploitation signal is solid enough to mandate federal remediation in three days.
If you read our September 5 exploitation coverage and filed this under “watching” rather than “patching,” the KEV addition changes the calculus. This is no longer a “monitor the threat intel” situation.
Fixed versions:
| Product | Fix in |
|---|---|
| NetScaler ADC/Gateway 14.1 | 14.1-73.32 |
| NetScaler ADC/Gateway 13.1 | 13.1-63.21 |
| NetScaler ADC FIPS 14.1 | 14.1-73.32 FIPS |
Full details: Citrix advisory CTX696939.
Priority three: Fortinet FortiOS CVE-2025-25249 (CVSS 8.1)
CVE-2025-25249 is a heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE. Crafted packets trigger unauthorized code execution. CISA added it to KEV September 9. Attackers are deploying PivotC2, a remote access trojan, in active exploitation. The fix has been available since January 2026.
CVSS 8.1 puts this below the other two, and the patch has been out longer. But “lower priority” between three actively exploited KEV flaws is a relative term. If you are running unpatched Fortinet hardware on an internet-accessible segment, this is a real threat. Full coverage and affected version matrix.
The pattern worth naming
All three were added to KEV in the same CISA batch on September 9, all with the same September 12 deadline. That means CISA had exploitation evidence on three separate vendor platforms simultaneously. The common thread is network perimeter and management infrastructure: Cisco’s firewall management console, Citrix’s application delivery and VPN gateway, Fortinet’s OS underpinning its firewall and switch management stack.
Attackers are focused on the control plane and the perimeter. Patch the management and edge layer first, then work inward.
For the September 2026 patch backlog more broadly, see also: Microsoft’s September Patch Tuesday (974 CVEs, two Windows zero-days, September 22 deadline) and Ivanti’s September patches (six critical RCEs).
- [ CRITICAL ]CVE-2026-20079Cisco FMC Authentication Bypass Enables Root OS Access
- [ CRITICAL ]CVE-2026-19490Critical authentication bypass in Citrix NetScaler ADC and Gateway
- [ HIGH ]CVE-2025-25249Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Found this useful? Share it.


