On 9 September CISA listed as actively exploited flaws in Cisco Secure Firewall Management Center, NetScaler ADC and Gateway, and FortiOS. The deadline for all three is 12 September. The Cisco one was disclosed back in March with the highest possible score.
- CVE-2026-20079, Cisco FMC: authentication bypass to root, CVSS 10.0 per Cisco, advisory of 4 March 2026.
- CVE-2026-19490, NetScaler ADC and Gateway configured as a Gateway or AAA server (on newer builds, also with SAML): authentication bypass, CVSS v4 9.3, bulletin of 19 August.
- CVE-2025-25249, FortiOS, FortiSwitchManager and FortiSASE: buffer overflow with code execution.
Six months passed between Cisco's advisory and the day the flaw entered the catalog of exploited vulnerabilities.
Cisco disclosed it on 4 March with a score of 10.0 and a fix. That is the maximum score: no login, remote, all the way to root. On 9 September CISA says it is now being used. For a device whose job is to manage the firewall, half a year is a long time.
Why devices like these
All three guard the network. The console that manages the firewall, the gateway employees use to come in from outside, the firewall itself. Break into one of them and you haven't entered one machine. You hold the door.
The deadline is three days. For the Chrome flaw from the same day CISA gave two weeks. The catalog doesn't explain the difference, but you can see it with the naked eye.
With Cisco there is something to check besides updating. If the management interface was reachable from the internet and has not been updated since March, the patch closes the door going forward, and only the logs can answer for the past.
Whoever administers any of the three checks today: version, internet access to the management interface, logs. In that order.