CISA Flags Four Actively Exploited Flaws in Fortinet, Citrix, Cisco and Chrome
The US Cybersecurity and Infrastructure Security Agency (CISA) has added four newly identified vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming they are being actively exploited by attackers. The affected products include Fortinet devices, Citrix NetScaler, Cisco Firewall Management Center and Google Chromium (the engine behind Chrome and other browsers).
The flaws range from buffer overflow issues to authentication bypass vulnerabilities that let attackers skip normal login checks by using alternate access paths. Because these products are widely used for network security, remote access and web browsing, exploitation could give attackers deep access to business systems, not just US government networks.
While CISA's directive requiring urgent patching technically applies only to US federal agencies, the agency is urging all organisations worldwide to treat KEV Catalog entries as high priority. Australian businesses running Fortinet, Citrix, Cisco or Chromium-based browsers should check whether they are affected and apply vendor patches as soon as possible.