CISA Adds Critical Cisco, Citrix, Fortinet, and MikroTik Flaws to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by September 12, 2026. These include an authentication bypass flaw in Cisco Secure Firewall Management Center (CVE-2026-20079), an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-19490), a heap-based buffer overflow in Fortinet FortiOS (CVE-2025-25249), and two MikroTik RouterOS vulnerabilities (CVE-2026-67277, CVE-2026-86060). Active exploitation of these flaws has been confirmed.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai