we_are_coded.by CODE · The world, decoded
БГ
CISA

Three devices that guard the network entered the catalog of exploited flaws in one day, with three days to patch

CISA · event date: 9 September 2026Security

On 9 September CISA listed as actively exploited flaws in Cisco Secure Firewall Management Center, NetScaler ADC and Gateway, and FortiOS. The deadline for all three is 12 September. The Cisco one was disclosed back in March with the highest possible score.

In short
  • CVE-2026-20079, Cisco FMC: authentication bypass to root, CVSS 10.0 per Cisco, advisory of 4 March 2026.
  • CVE-2026-19490, NetScaler ADC and Gateway configured as a Gateway or AAA server (on newer builds, also with SAML): authentication bypass, CVSS v4 9.3, bulletin of 19 August.
  • CVE-2025-25249, FortiOS, FortiSwitchManager and FortiSASE: buffer overflow with code execution.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Six months passed between Cisco's advisory and the day the flaw entered the catalog of exploited vulnerabilities.

Cisco disclosed it on 4 March with a score of 10.0 and a fix. That is the maximum score: no login, remote, all the way to root. On 9 September CISA says it is now being used. For a device whose job is to manage the firewall, half a year is a long time.

The facts: on 9 September 2026 CISA added three vulnerabilities in network security devices to the KEV catalog, all with a deadline of 12 September. CVE-2026-20079 in Cisco Secure Firewall Management Center (FMC) and Cisco Security Cloud Control Firewall Management allows an unauthenticated remote attacker to bypass authentication and execute scripts with root access; Cisco's advisory was published on 4 March 2026 with CVSS 10.0 and no workaround, and Cisco notes that if the management interface has no internet access, the attack surface is reduced. CVE-2026-19490 in NetScaler ADC and NetScaler Gateway is an authentication bypass when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, and on newer builds only when a SAML action is configured; bulletin CTX696939 dates from 19 August, with CVSS v4 9.3 and fixed versions 14.1-73.32 and 13.1-63.21. CVE-2025-25249 in FortiOS, FortiSwitchManager and FortiSASE is a heap-based buffer overflow allowing code execution via specially crafted packets; Fortinet's advisory is FG-IR-25-084.

Why devices like these

All three guard the network. The console that manages the firewall, the gateway employees use to come in from outside, the firewall itself. Break into one of them and you haven't entered one machine. You hold the door.

The guard at the entrance is the most valuable target in the building.

The deadline is three days. For the Chrome flaw from the same day CISA gave two weeks. The catalog doesn't explain the difference, but you can see it with the naked eye.

With Cisco there is something to check besides updating. If the management interface was reachable from the internet and has not been updated since March, the patch closes the door going forward, and only the logs can answer for the past.

Whoever administers any of the three checks today: version, internet access to the management interface, logs. In that order.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog (official catalog)→Cisco - Secure Firewall Management Center Software Authentication Bypass Vulnerability (cisco-sa-onprem-fmc-authbypass-5JPp45V2), 04.03.2026→NetScaler (Cloud Software Group) - Security Bulletin CTX696939, 19.08.2026→Fortinet PSIRT - FG-IR-25-084
Original: https://wearecoded.com/en/articles/kev-cisco-fmc-netscaler-fortios-tri-dni.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news