การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Vulnerability

CISA Warns of Active Exploitation in Fortinet, Citrix, Cisco, and Chromium Systems

FORTSECURE GLOBAL· 2026-09-10🛰 CISA Cybersecurity Advisories
#Vulnerability#Cisco#Fortinet#Network Security#Application Security

CISA has updated its Known Exploited Vulnerabilities catalog with critical flaws affecting Fortinet, Citrix, Cisco, and Google Chromium that are under active attack.

The Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of weaponization in the wild. The newly listed security flaws encompass major enterprise software and network appliances, including products from Fortinet, Citrix NetScaler, Google Chromium, and Cisco Firewall Management Center.

Among the cataloged weaknesses are high-risk vulnerabilities such as CVE-2025-25249, a heap-based buffer overflow flaw impacting Fortinet devices, and CVE-2026-19490, which allows authentication bypass via alternate channels in Citrix NetScaler systems. Additionally, Google Chromium's V8 engine suffers from an out-of-bounds write flaw (CVE-2026-87491), and Cisco Firewall Management Center is exposed through an authentication bypass vulnerability (CVE-2026-20079). These flaws grant attackers pathways to execute arbitrary code or bypass security perimeter defenses entirely.

Mitigation and Practical Recommendations

Because threat actors routinely target perimeter appliances and web browsers to gain initial access, FORTSECURE GLOBAL strongly advises organizations to enforce immediate remediation controls:

  • Expedite Patch Deployment: Prioritize patching internet-facing appliances, particularly Citrix NetScaler and Cisco FMC instances, following vendor security bulletins.
  • Enforce Strict Access Controls: Restrict administrative management interfaces from the public internet using private networks or VPN access protected with multi-factor authentication (MFA).
  • Audit Vulnerability Exposure: Continuously cross-reference enterprise asset inventories against CISA's KEV Catalog to detect and isolate unpatched assets rapidly.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Wed, 09 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Wed, 09 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog