INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

U.S. CISA Adds Flaws to Known Exploited Vulnerabilities

| 2026-09-10 18:57 CRITICAL HIGH
Executive Summary AI-generated
The situation is critical, with multiple high-severity vulnerabilities being exploited in the wild. The most recent incident data reveals that Google fixed a heap-based buffer overflow vulnerability (CVE-2026-87491) in Chrome 153.0.8010.36 and later versions. This flaw allows unauthenticated remote attackers to bypass authentication and execute scripts, potentially gaining root access to the underlying operating system. The vulnerabilities are being actively exploited by attackers, including those using PivotC2 remote access trojan on compromised FortiGate devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these flaws to its Known Exploited Vulnerabilities catalog, with a deadline of September 22, 2026, for federal agencies to fix the vulnerabilities. The identified entities responsible for this vulnerability are Cisco Secure FMC's web interface, Google Chromium V8, Fortinet, and Citrix NetScaler. The MITRE ATT&CK technique used is authentication bypass using an alternate path or channel.
Technical Mitigations AI-generated
* Implement a secure coding practice to prevent heap-based buffer overflow vulnerabilities, such as using safe functions and input validation. * Regularly update and patch Fortinet products, including FortiOS and FortiSwitchManager, to ensure timely fixes for known exploits like CVE-2026-87491. * Configure Citrix NetScaler ADC and NetScaler Gateway to use secure authentication mechanisms, such as SAML HTTP-Redirect binding with proper authorization checks. * Monitor network traffic and system logs for signs of unauthorized access attempts using authentication bypass vulnerabilities like those found in CVE-2025-25249 (Cisco) and CVE-2026-87491 (Google Chromium V8). * Implement a web application firewall (WAF) to detect and block malicious HTTP requests, such as those used by attackers to execute arbitrary code on compromised systems.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-19490CVE-2026-19490 CVE-2025-25249CVE-2025-25249 CVE-2026-87491CVE-2026-87491 CVE-2026-20079CVE-2026-20079
Target & Sectors
RU
Incident Timeline
‎July 2026
Threat actors used a known exploit of the Citrix NetScaler vulnerability to target U.S. CISA in July 2026.
‎2026/08/11
Threat actors used a custom malware to target Cisco IOS XR routers and exploit known vulnerabilities in the affected devices.
source_region China
tactic Espionage
infrastructure Ios
organisation Sygnia
‎August 2026
Threat actors used a known exploit of CVE-2026-20079 to target Cisco systems.
vulnerability CVE-2026-20079
‎September 3, 2026
Threat actors used a known exploit of CVE-2026-19490 to target Previdian's honeypot systems.
vulnerability CVE-2026-19490
organisation Previdian
general_metric 56 attempts
‎September 8, 2026
Threat actors used a combination of vulnerabilities in Cisco, Google Chromium V8, Fortinet and Citrix NetScaler to gain unauthorized access.
general_metric 36 attempts
‎September 10, 2026
Threat actors used a heap-based buffer overflow vulnerability in Cisco Secure FMC's web interface to target Citrix NetScaler ADC and NetScaler Gateway, allowing unauthenticated remote attackers to bypass authentication through the SAML HTTP-Redirect binding.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution Citrix NetScaler
organisation CVE-2025-25249
organisation Fortinet FortiOS
organisation CVE-2026
infrastructure 153.0.8010
infrastructure Fortigate
organisation FortiGate
organisation Cisco Secure FMC’s
organisation Google
organisation WebAssembly
organisation HTML
organisation Citrix NetScaler ADC
organisation NetScaler Gateway
‎Sep 10, 2026
U.S. CISA added the identified vulnerabilities to its Known Exploited Vulnerabilities catalog on September 10, 2026.
‎2026/09/10
Threat actors used Fortinet products to target U.S. CISA, exploiting vulnerabilities in Cisco Secure Firewall Management Center Software and Citrix NetScaler ADC and NetScaler Gateway when configured as AAA virtual servers or Gateways.
organisation CVE-2025-25249
organisation KEV
organisation Fortinet FortiOS
infrastructure Fortigate
organisation SOCRadar
organisation Citrix NetScaler ADC
organisation NetScaler Gateway
organisation AAA
organisation ICA
organisation Cisco Secure Firewall Management Center
organisation IP
infrastructure 3,000 IP addresses
infrastructure 178 devices
organisation Fortinet
‎September 12, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added vulnerabilities to Cisco, Citrix, and Fortinet in Windows systems to its Known Exploited Vulnerabilities catalog.
infrastructure Windows
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution FCEB
attribution Vulnerability / Network Security
attribution Fortinet
attribution Federal Civilian Executive Branch
general_metric 10 Sep
general_metric 2026 Sep
‎Sept. 12
Threat actors exploited vulnerabilities in Fortinet products, including the Cisco product and Citrix NetScaler, to gain unauthorized access.
attribution Fortinet Flaws
‎September 22, 2026
Threat actors exploited vulnerabilities in Windows to gain unauthorized access.
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎153.0.8010
Software Version
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
3,000
Ip Addresses
Metrics
infrastructure
178
Devices