Exploited Cisco, Citrix, Fortinet Flaws

Overview

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three critical vulnerabilities impacting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog. Federal Civilian Executive Branch (FCEB) agencies must patch these flaws by September 12, 2026, under Binding Operational Directive (BOD) 22‑01.

Vulnerabilities Added to KEV

  • CVE‑2026‑20079 (CVSS 10.0): Authentication bypass in Cisco Secure Firewall Management Center (FMC) web interface. Allows unauthenticated attackers to bypass authentication and execute scripts, gaining root access.
  • CVE‑2026‑19490 (CVSS 9.3): Authentication bypass in Citrix NetScaler ADC and Gateway when configured as AAA virtual server or SSL VPN/ICA Proxy/RDP Proxy.
  • CVE‑2025‑25249 (CVSS 7.3): Heap‑based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE, enabling arbitrary code execution via crafted requests.

Exploitation Activity

  • Cisco (CVE‑2026‑20079): Active exploitation confirmed in August 2026. Cisco routers have long been targeted, with Fire Ant, a China‑nexus group, abusing Cisco IOS XR routers for persistence and data collection.
  • Citrix (CVE‑2026‑19490): Honeypot systems recorded 56 exploitation attempts since September 3, 2026, with 36 attempts on September 8 alone.
  • Fortinet (CVE‑2025‑25249): Weaponized in campaigns delivering PivotC2, a Node.js remote access trojan.
    • Features: interactive shells, tunneling, scanning, credential harvesting.
    • Impact: 178 devices infected, mostly in the U.S., linked to a Russian‑speaking financially motivated actor.

Attack Chain Example (Fortinet PivotC2)

  1. Exploit binary targets vulnerable FortiGate instance.
  2. Reverse shell established.
  3. Node.js one‑liner downloads second‑stage payload.
  4. Payload decrypted and executed → PivotC2 delivered.
  5. Persistent outbound TLS connection established to C2 server.

Defensive Guidance

Organizations should:

  • Apply patches immediately before Sept. 12 deadline.
  • Limit internet exposure for Cisco, Citrix, and Fortinet appliances.
  • Hunt for IoCs associated with PivotC2 and authentication bypass attempts.
  • Rotate credentials and review privileged accounts.
  • Monitor logs for unusual authentication or reverse shell activity.

Expert in the Cloud Insight

The addition of these flaws to the KEV catalog highlights a recurring theme: perimeter edge devices remain the most attractive targets for attackers. Whether through authentication bypass or buffer overflow, adversaries exploit weak monitoring and patch delays to gain footholds. The lesson is clear: patch fast, restrict exposure, and monitor aggressively to prevent ransomware and espionage campaigns from leveraging these vulnerabilities.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.