INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
U.S. CISA Adds Flaws to Known Exploited Vulnerabilities
| 2026-09-10 18:57 CRITICAL HIGHExecutive Summary AI-generated
The situation is critical, with multiple high-severity vulnerabilities being exploited in the wild. The most recent incident data reveals that Google fixed a heap-based buffer overflow vulnerability (CVE-2026-87491) in Chrome 153.0.8010.36 and later versions. This flaw allows unauthenticated remote attackers to bypass authentication and execute scripts, potentially gaining root access to the underlying operating system.
The vulnerabilities are being actively exploited by attackers, including those using PivotC2 remote access trojan on compromised FortiGate devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these flaws to its Known Exploited Vulnerabilities catalog, with a deadline of September 22, 2026, for federal agencies to fix the vulnerabilities.
The identified entities responsible for this vulnerability are Cisco Secure FMC's web interface, Google Chromium V8, Fortinet, and Citrix NetScaler. The MITRE ATT&CK technique used is authentication bypass using an alternate path or channel.
Technical Mitigations AI-generated
* Implement a secure coding practice to prevent heap-based buffer overflow vulnerabilities, such as using safe functions and input validation.
* Regularly update and patch Fortinet products, including FortiOS and FortiSwitchManager, to ensure timely fixes for known exploits like CVE-2026-87491.
* Configure Citrix NetScaler ADC and NetScaler Gateway to use secure authentication mechanisms, such as SAML HTTP-Redirect binding with proper authorization checks.
* Monitor network traffic and system logs for signs of unauthorized access attempts using authentication bypass vulnerabilities like those found in CVE-2025-25249 (Cisco) and CVE-2026-87491 (Google Chromium V8).
* Implement a web application firewall (WAF) to detect and block malicious HTTP requests, such as those used by attackers to execute arbitrary code on compromised systems.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-19490CVE-2026-19490
CVE-2025-25249CVE-2025-25249
CVE-2026-87491CVE-2026-87491
CVE-2026-20079CVE-2026-20079
Target & Sectors
RU
Incident Timeline
July 2026
Threat actors used a known exploit of the Citrix NetScaler vulnerability to target U.S. CISA in July 2026.
2026/08/11
Threat actors used a custom malware to target Cisco IOS XR routers and exploit known vulnerabilities in the affected devices.
Click on any entity below to view its context and source!
source_region
China
In a report published late last month, Sygnia
said
it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.
tactic
Espionage
In a report published late last month, Sygnia
said
it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.
infrastructure
Ios
In a report published late last month, Sygnia
said
it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.
organisation
Sygnia
In a report published late last month, Sygnia
said
it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.
August 2026
Threat actors used a known exploit of CVE-2026-20079 to target Cisco systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-20079
The development comes as Cisco
updated its advisory
for CVE-2026-20079 to note that it became aware of active exploitation efforts targeting the flaw in August 2026.
September 3, 2026
Threat actors used a known exploit of CVE-2026-19490 to target Previdian's honeypot systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-19490
"
CVE-2026-19490, on the other hand, has
witnessed
exploitation activity targeting Previdian's honeypot systems, with a total of 56 attempts registered since September 3, 2026.
organisation
Previdian
"
CVE-2026-19490, on the other hand, has
witnessed
exploitation activity targeting Previdian's honeypot systems, with a total of 56 attempts registered since September 3, 2026.
general_metric
56 attempts
"
CVE-2026-19490, on the other hand, has
witnessed
exploitation activity targeting Previdian's honeypot systems, with a total of 56 attempts registered since September 3, 2026.
September 8, 2026
Threat actors used a combination of vulnerabilities in Cisco, Google Chromium V8, Fortinet and Citrix NetScaler to gain unauthorized access.
Click on any entity below to view its context and source!
general_metric
36 attempts
Of these, 36 attempts were
recorded
on September 8, 2026, alone.
September 10, 2026
Threat actors used a heap-based buffer overflow vulnerability in Cisco Secure FMC's web interface to target Citrix NetScaler ADC and NetScaler Gateway, allowing unauthenticated remote attackers to bypass authentication through the SAML HTTP-Redirect binding.
Click on any entity below to view its context and source!
attribution
Known Exploited
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 10, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 10, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
attribution
Citrix NetScaler
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 10, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog.
organisation
CVE-2025-25249
CVE-2025-25249
(CVSS score of 8.1) is a heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiSwitchManager.
organisation
Fortinet FortiOS
CVE-2025-25249
(CVSS score of 8.1) is a heap-based buffer overflow vulnerability in Fortinet FortiOS and FortiSwitchManager.
organisation
CVE-2026
“Google is aware that an exploit for CVE-2026-87491 exists in the wild.”
reads the advisory
.
infrastructure
153.0.8010
Google fixed the issue in Chrome 153.0.8010.36 and later versions.
infrastructure
Fortigate
The vulnerability is being actively exploited in the wild, including in attacks that deployed the PivotC2 remote access trojan on compromised FortiGate devices.
organisation
FortiGate
The vulnerability is being actively exploited in the wild, including in attacks that deployed the PivotC2 remote access trojan on compromised FortiGate devices.
organisation
Cisco Secure FMC’s
The flaw resides in Cisco Secure FMC’s web interface and lets unauthenticated remote attackers bypass authentication and send crafted HTTP requests to execute scripts, potentially gaining root access to the underlying operating system.
organisation
Google
The bug affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine.
organisation
WebAssembly
The bug affects V8, Google’s open source high-performance JavaScript and WebAssembly engine, Chrome’s JavaScript and WebAssembly engine.
organisation
HTML
An attacker can exploit the out-of-bounds write through a specially crafted HTML page and execute arbitrary code inside Chrome’s sandbox.
organisation
Citrix NetScaler ADC
The flaw affects Citrix NetScaler ADC and NetScaler Gateway and allows unauthenticated remote attackers to bypass authentication through the SAML HTTP-Redirect binding, potentially gaining unauthorized access to protected services.
organisation
NetScaler Gateway
The flaw affects Citrix NetScaler ADC and NetScaler Gateway and allows unauthenticated remote attackers to bypass authentication through the SAML HTTP-Redirect binding, potentially gaining unauthorized access to protected services.
Sep 10, 2026
U.S. CISA added the identified vulnerabilities to its Known Exploited Vulnerabilities catalog on September 10, 2026.
2026/09/10
Threat actors used Fortinet products to target U.S. CISA, exploiting vulnerabilities in Cisco Secure Firewall Management Center Software and Citrix NetScaler ADC and NetScaler Gateway when configured as AAA virtual servers or Gateways.
Click on any entity below to view its context and source!
organisation
CVE-2025-25249
CVE-2025-25249
(CVSS score: 7.3) -
organisation
KEV
The addition of CVE-2025-25249 to the KEV catalog follows a
report
from SOCRadar about a malicious attack campaign that's suspected to have weaponized the flaw to deliver a feature-rich Node.js remote access trojan (RAT) codenamed PivotC2.
organisation
Fortinet FortiOS
A heap-based buffer overflow vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that could allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
infrastructure
Fortigate
In the observed attacks, a shell script containing an exploit binary targets a vulnerable FortiGate instance to establish a reverse shell and run a single-line JavaScript command via Node.js.
Its feature set includes interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, local and remote port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption," SOCRadar said.
organisation
SOCRadar
Its feature set includes interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, local and remote port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption," SOCRadar said.
organisation
Citrix NetScaler ADC
An authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
organisation
NetScaler Gateway
An authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
organisation
AAA
An authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
organisation
ICA
An authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy).
organisation
Cisco Secure Firewall Management Center
An authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
organisation
IP
More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2.
infrastructure
3,000 IP addresses
More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2.
infrastructure
178 devices
More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2.
organisation
Fortinet
SOCRadar is recommending organizations using Fortinet products to limit internet access, hunt for indicators of compromise, rotate credentials, and apply the latest patches.
September 12, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added vulnerabilities to Cisco, Citrix, and Fortinet in Windows systems to its Known Exploited Vulnerabilities catalog.
Click on any entity below to view its context and source!
infrastructure
Windows
CISA orders federal agencies to fix the Windows flaws by September 22, 2026, while the remaining must be addressed by September 12, 2026.
attribution
Known Exploited
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
tactic
T1588.006 - Vulnerabilities
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
KEV
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
FCEB
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
Vulnerability / Network Security
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
Fortinet
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
attribution
Federal Civilian Executive Branch
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
general_metric
10 Sep
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
general_metric
2026 Sep
Ravie Lakshmanan
Sep 10, 2026
Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday
added
three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
Sept. 12
Threat actors exploited vulnerabilities in Fortinet products, including the Cisco product and Citrix NetScaler, to gain unauthorized access.
Click on any entity below to view its context and source!
attribution
Fortinet Flaws
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline.
September 22, 2026
Threat actors exploited vulnerabilities in Windows to gain unauthorized access.
Click on any entity below to view its context and source!
infrastructure
Windows
CISA orders federal agencies to fix the Windows flaws by September 22, 2026, while the remaining must be addressed by September 12, 2026.
Tactical Metrics
Metrics
infrastructure
153.0.8010
Software Version
Click for context!
Google fixed the issue in Chrome 153.0.8010.36 and later versions.
Metrics
infrastructure
Fortigate
Affected Product
The vulnerability is being actively exploited in the wild, including in attacks that deployed the PivotC2 remote access trojan on compromised FortiGate devices.
In the observed attacks, a shell script containing an exploit binary targets a vulnerable FortiGate instance to establish a reverse shell and run a single-line JavaScript command via Node.js.
Its feature set includes interactive shells, file transfers, SOCKS5/HTTP proxy tunneling, local and remote port forwarding, CIDR-range scanning, and FortiGate-specific configuration harvesting and credential decryption," SOCRadar said.
Metrics
infrastructure
Windows
Affected Product
CISA orders federal agencies to fix the Windows flaws by September 22, 2026, while the remaining must be addressed by September 12, 2026.
Metrics
infrastructure
Ios
Affected Product
In a report published late last month, Sygnia
said
it observed a China-nexus cyber espionage group dubbed Fire Ant obtaining unauthorized access to Cisco IOS XR routers and abusing them to facilitate persistence, data collection, and burrow deeper into high-value networks via custom malware.
Metrics
infrastructure
3,000
Ip Addresses
More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2.
Metrics
infrastructure
178
Devices
More than 3,000 IP addresses are estimated to have been targeted as part of the campaign, resulting in the infection of 178 devices with PivotC2.
Intelligence Sources
Security Affairs
2026-09-10
The Hacker News
2026-09-10
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-11T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
19x
organisation
Identified Entity
CVE-2026
entity
18x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
12x
timeline
Temporal Reference
September 10, 2026
date
4x
vulnerability
Exploited CVE
CVE-2025-25249
cve
4x
vulnerability
CVSS Score
10
score
4x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
3x
infrastructure
Affected Product
Fortigate
software
2x
tactic
Cyber Operation Type
Buffer Overflow
tactic
2x
general metric
Cvss Score
9
cvss score
2x
general metric
Attempts
56
attempts
2x
general metric
Sep
10
sep
Contextual Telemetry
Context Block
5 METRICS
infrastructure
Software Version
153.0.8010
version
source region
Origin Country
China
country
target region
Target Country
Russian Federation
country
infrastructure
Ip Addresses
3,000
ip addresses
infrastructure
Devices
178
devices
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.