Skip to content
feed: live
>_0dayNews
Briefing · 2026-09-11

Sep 11: Cisco FMC, Fortinet Hit KEV; Sept. 12 Deadline

Cisco FMC CVSS 10.0 auth bypass and Fortinet FortiOS heap overflow confirmed exploited, added to CISA KEV with September 12 deadline. Ivanti patches six critical RCEs. SAP closes CVSS 10.0 EPP flaw.

tldr.txt
  • CVE-2026-20079 (Cisco FMC, CVSS 10.0): confirmed exploited, CISA KEV, September 12 federal deadline. Unauthenticated attackers reach root on the FMC management plane. Cisco Talos reports three separate threat clusters active, including ransomware operators and state-sponsored actors.
  • CVE-2025-25249 (Fortinet FortiOS/FortiSwitchManager/FortiSASE, CVSS 8.1): confirmed exploited with PivotC2 RAT, CISA KEV, September 12 federal deadline. Patch has been available since January 2026.
  • Ivanti September 2026 patches: six critical RCEs in Neurons for ITSM, plus auth bypass flaws in Sentry and EPMM. No confirmed exploitation in the wild reported as of September 10.
  • SAP September Patch Day: CVSS 10.0 unauthenticated RCE in Extended Passport Processing (EPP). Multiple additional critical notes released.
  • Veradigm patient data breach: third-party vendor compromise disclosed after Gentlemen ransomware gang claimed responsibility.

Two active exploitation confirmations from CISA in one day. Both carry a September 12 federal deadline. That deadline is tomorrow.

Cisco FMC CVE-2026-20079: CVSS 10.0, three threat clusters confirmed

CVE-2026-20079 is an authentication bypass in Cisco Secure Firewall Management Center and Security Cloud Control. CVSS 10.0. Network-reachable, no credentials required, no user interaction. Successful exploitation gives the attacker root on the OS underlying FMC.

Cisco confirmed active exploitation September 9. CISA added it to the Known Exploited Vulnerabilities catalog the same day with a remediation deadline of September 12.

After publication of Cisco’s advisory and our initial coverage, Cisco Talos released additional intelligence: three distinct threat clusters are exploiting CVE-2026-20079, including actors linked to ransomware operations and state-sponsored activity. Talos tracked exploitation of FMC vulnerabilities across multiple recent intrusions.

FMC is the management plane for Cisco Secure Firewall deployments. Compromise of FMC means access to every firewall policy, rule set, and traffic log on devices it manages. This is the second Cisco FMC CVE to reach KEV in 2026. CVE-2026-20316 was the first, in July.

Patch path: Cisco advisory cisco-sa-onprem-fmc-authbypass-5JPp45V2.

Fortinet CVE-2025-25249: nine months after patch, actively exploited

CVE-2025-25249 is a heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE. CVSS 8.1. Specially crafted packets trigger unauthorized code execution. CISA added it to KEV September 9. September 12 deadline applies.

The threat actor post-exploitation payload is PivotC2, a remote access trojan. Technical details on PivotC2’s persistence mechanism and command infrastructure remain limited at this stage. Exploitation is confirmed; attribution beyond “three threat clusters” per Talos has not been publicly released.

The patch shipped January 2026. The gap between fix and confirmed exploitation: nine months.

Affected versions span FortiOS 6.4 through 7.6.3, FortiSwitchManager 7.0 through 7.2.6, and FortiSASE. Fix versions are documented in the NVD entry at nvd.nist.gov/vuln/detail/CVE-2025-25249. Full coverage.

Ivanti September patches: six critical RCEs, no confirmed exploitation

Ivanti released its September 2026 patches September 10. Six critical-severity RCEs affect Neurons for ITSM. Auth bypass vulnerabilities affect Sentry and EPMM. No confirmed exploitation reported as of publication.

Ivanti’s patch record over the past 24 months means “no confirmed exploitation at publication” should not be read as low urgency for perimeter-facing Ivanti products. Full version matrix and patch guidance.

Also noted

  • SAP September Patch Day: CVSS 10.0 unauthenticated RCE in Extended Passport Processing (EPP). Multiple additional critical Security Notes released. Coverage.
  • Veradigm breach: patient data compromised via a third-party vendor. Gentlemen ransomware gang claimed responsibility. Veradigm disclosed September 10. Coverage.
  • Microsoft September Patch Tuesday (September 8): 974 CVEs, two exploited Windows privilege escalation zero-days on CISA KEV. Remediation deadline: September 22. Coverage.
Sources