← All articles

CISA flags exploited Cisco, Citrix, Fortinet, and WatchGuard edge flaws

CISA added several actively exploited flaws in internet-facing security appliances to its catalog, ordering federal agencies to patch by September 12. The most severe, CVE-2026-20079 scored 10.0, is an authentication bypass in Cisco Secure Firewall Management Center that lets an unauthenticated attacker run scripts and gain root on the device; Cisco confirmed exploitation since August. A Citrix NetScaler authentication bypass, CVE-2026-19490, saw a surge of attacks on September 8, and a Fortinet FortiOS flaw, CVE-2025-25249, is being used to deliver a remote access trojan. Separately, CISA warned that a critical WatchGuard Firebox firewall flaw is now being exploited in ransomware attacks. Edge appliances remain prime targets.

Check
Immediately patch internet-facing Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, and WatchGuard Firebox devices to fixed versions, prioritizing anything reachable from the internet, and hunt exposed appliances for signs of compromise.
Affected
Organizations running affected Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, or WatchGuard Firebox appliances (CVE-2026-20079, CVE-2026-19490, CVE-2025-25249); all are exploited, from unauthenticated root access to RAT and ransomware deployment.
Fix
Patch these appliances now given the short federal deadline and active exploitation, restrict management interfaces from the internet, monitor for auth-bypass and script-execution activity, and treat any exposed unpatched device as compromised.