CISA's list that day
9 September 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Fortinet Multiple Products, Citrix NetScaler, Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management and 1 other product. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-20079Firewall Management Center Authentication Bypass Using an Alternate Path or Channel | Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Patch nowForensic triage required by CISA; Metasploit module | 0.88 | ||
| CVE-2026-19490Authentication Bypass Using an Alternate Path or Channel | Citrix NetScaler | Patch nowForensic triage required by CISA | 0.23 | ||
| CVE-2025-25249Heap-based Buffer Overflow | Fortinet Multiple Products | Patch nowForensic triage required by CISA | 0.04 | ||
| CVE-2026-87491Out of Bounds Write | Google Chromium V8 | Patch soon | 0.03 |