CISA Warns of Active Attacks on Cisco, Citrix and Fortinet Flaws, Sets Patch Deadline
The US Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities affecting Cisco, Citrix and Fortinet products to its Known Exploited Vulnerabilities catalog after confirming they are being actively exploited. Federal agencies must patch by 12 September 2026, but the flaws pose a risk to any organisation running these products.
The Cisco flaw (CVE-2026-20079) has already been linked to a China-based espionage group that compromised Cisco IOS XR routers, turning them into surveillance points capable of monitoring traffic across trusted network paths rather than simply passing it through. The Citrix flaw (CVE-2026-19490) has seen a spike in scanning and exploitation attempts against honeypot systems, with dozens of attempts recorded in a single day earlier this month.
The Fortinet flaw (CVE-2025-25249) has been tied to a financially motivated campaign, believed to involve a Russian-speaking threat actor, that delivers a remote access trojan called PivotC2. This malware gives attackers remote shell access, network scanning capability and the ability to harvest device configurations. Thousands of IP addresses have reportedly been targeted, with confirmed infections mostly in the United States since at least July 2026.