Vulnerability
CISA Warns of Active Exploitation in Fortinet, Citrix, Cisco, and Chromium Systems
CISA has updated its Known Exploited Vulnerabilities catalog with critical flaws affecting Fortinet, Citrix, Cisco, and Google Chromium that are under active attack.
The Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of weaponization in the wild. The newly listed security flaws encompass major enterprise software and network appliances, including products from Fortinet, Citrix NetScaler, Google Chromium, and Cisco Firewall Management Center.
Among the cataloged weaknesses are high-risk vulnerabilities such as CVE-2025-25249, a heap-based buffer overflow flaw impacting Fortinet devices, and CVE-2026-19490, which allows authentication bypass via alternate channels in Citrix NetScaler systems. Additionally, Google Chromium's V8 engine suffers from an out-of-bounds write flaw (CVE-2026-87491), and Cisco Firewall Management Center is exposed through an authentication bypass vulnerability (CVE-2026-20079). These flaws grant attackers pathways to execute arbitrary code or bypass security perimeter defenses entirely.
Mitigation and Practical Recommendations
Because threat actors routinely target perimeter appliances and web browsers to gain initial access, FORTSECURE GLOBAL strongly advises organizations to enforce immediate remediation controls:
- Expedite Patch Deployment: Prioritize patching internet-facing appliances, particularly Citrix NetScaler and Cisco FMC instances, following vendor security bulletins.
- Enforce Strict Access Controls: Restrict administrative management interfaces from the public internet using private networks or VPN access protected with multi-factor authentication (MFA).
- Audit Vulnerability Exposure: Continuously cross-reference enterprise asset inventories against CISA's KEV Catalog to detect and isolate unpatched assets rapidly.
แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Wed, 09 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: CISA Cybersecurity Advisories
เผยแพร่ครั้งแรก: Wed, 09 Sep 26 12:00:00 +0000
บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
