CISA's list that day

9 September 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in Fortinet Multiple Products, Citrix NetScaler, Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management and 1 other product. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-20079Firewall Management Center Authentication Bypass Using an Alternate Path or ChannelCisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementPatch nowForensic triage required by CISA; Metasploit module0.88
CVE-2026-19490Authentication Bypass Using an Alternate Path or ChannelCitrix NetScalerPatch nowForensic triage required by CISA0.23
CVE-2025-25249Heap-based Buffer OverflowFortinet Multiple ProductsPatch nowForensic triage required by CISA0.04
CVE-2026-87491Out of Bounds WriteGoogle Chromium V8Patch soon0.03

Other changes that day

  1. CVE-2016-7255 Microsoft Win32kRansomware use: Unknown to Known.
  2. CVE-2019-0859 Microsoft Win32kRansomware use: Unknown to Known.
  3. CVE-2022-41352 Synacor Zimbra Collaboration Suite (ZCS)Ransomware use: Unknown to Known.