Federal deadline passes as attackers keep exploiting Cisco, Citrix and Fortinet flaws
CISA gave federal agencies until September 12 to patch three actively exploited flaws in widely used firewall and VPN gateway software. Researchers say a Russian state-linked group, a ransomware affiliate and a criminal campaign that infected 178 devices are still breaking in.

A federal deadline to patch three actively exploited vulnerabilities in some of the most widely deployed network security products on the market passed this week, and researchers say attackers, including a Russian state-linked group and at least one ransomware affiliate, are still breaking in through the holes. The flaws sit in Cisco's Secure Firewall Management Center, Citrix's NetScaler application-delivery and remote-access gateways, and Fortinet's FortiOS operating system, three product lines that collectively secure the network perimeter of tens of thousands of corporate and government networks.
The Cybersecurity and Infrastructure Security Agency added all three flaws to its Known Exploited Vulnerabilities catalog on September 9, triggering a binding directive that gave civilian federal agencies until September 12 to apply fixes or take affected systems offline. That deadline has now passed, but the vulnerabilities remain unpatched on an unknown number of systems outside the federal government, where compliance is only encouraged, not required, and security researchers report exploitation attempts continuing into this week.
The numbers
The most severe of the three is a Cisco flaw, tracked as CVE-2026-20079, which carries the maximum possible severity score of 10.0 out of 10 on the Common Vulnerability Scoring System. It lets an attacker with no credentials send crafted requests to the web interface of Secure Firewall Management Center software and obtain root-level control of the device. Cisco's own security advisory says the bug was first fixed in March, when the company had no evidence it was being abused; its Talos threat-intelligence unit confirmed active exploitation in August.
The Citrix flaw, CVE-2026-19490, scores 9.3 and allows an unauthenticated attacker to bypass login controls on NetScaler ADC and NetScaler Gateway appliances configured as a remote-access gateway or authentication server. Citrix published fixed builds in an August 19 security bulletin, three weeks before CISA confirmed the bug was being exploited. The Fortinet flaw, CVE-2025-25249, is comparatively lower-severity at 7.3 but has been exploited the longest: a heap-based buffer overflow in FortiOS and FortiSwitchManager that Fortinet's own PSIRT advisory says was patched in January. Researchers at the threat-intelligence firm SOCRadar say a campaign exploiting it has scanned more than 30,000 internet-facing IP addresses since at least July and successfully compromised 178 devices, installing a custom remote-access tool the researchers named PivotC2.
How the flaws surfaced
Each of the three vulnerabilities had been known and patched, in some cases for months, before evidence of exploitation emerged. That pattern is now routine for a category of software security researchers have taken to calling "edge devices": firewalls, VPN concentrators and load balancers that sit at the boundary of a corporate network, are reachable from the open internet by design, and, once compromised, hand an intruder a foothold from which to move inward. Products from Ivanti, Citrix and Fortinet have each supplied at least one marquee incident in the last three years in which nation-state or ransomware operators reverse-engineered a vendor's patch, or found an unpatched variant of the same bug class, faster than customers could roll updates out.
Cisco's Talos unit says it has identified three distinct clusters of activity abusing the Secure Firewall Management Center flaw since it went public. One deploys web shells into the product's Tomcat application server to harvest administrator credentials. A second, which Talos links to the Russian state-linked group tracked as Sandworm, modifies internal licensing files to open a reverse shell and steal firewall configuration data, including VPN credentials. A third, associated with the Qilin ransomware operation, uses stolen static credentials to move through a network before deploying antivirus-disabling tools and ransomware, according to reporting on Talos's findings by Help Net Security.
Who is exposed
The direct legal obligation to patch by September 12 applied only to civilian agencies of the U.S. federal government, which CISA's binding operational directive covers. But the vulnerable products are run by state and local governments, hospital systems, universities and companies across every industry that uses Cisco firewalls, Citrix remote-access gateways or Fortinet network gear to secure their perimeter. Fortinet devices in particular have a long tail of unpatched installations; the flaw being exploited by the PivotC2 campaign was fixed in January, meaning the 178 compromised devices SOCRadar identified had gone eight months without the update. SOCRadar's researchers said the majority of compromises they observed were concentrated among organizations in the United States, and that at least two intrusions had already resulted in data being stolen from the victim's network before it was discovered.
"Due to Talos identifying in the wild abuse of these CVEs, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco."
Cisco has said hotfixes will stop new exploitation but will not remove an intruder who has already established a foothold on a device, meaning administrators who find evidence of compromise need to treat the appliance as breached and investigate accordingly rather than simply patching and moving on. The company has said a more comprehensive software update, intended to close the underlying design issue rather than just the exploited symptom, is expected the week of September 16.
What happens next
For Citrix customers, the fix is more straightforward: upgrade NetScaler ADC and Gateway appliances to the builds Citrix has published, and disable AAA virtual server or gateway configurations on any device that cannot be updated immediately. Fortinet's patch has been available since January, so the remaining exposure is largely a matter of finding and updating devices that were missed the first time. CISA's own guidance, echoed by every vendor involved, is that organizations outside the federal government should treat the September 12 deadline as a floor rather than an irrelevant federal formality, given that the same exploitation activity CISA cited in adding the bugs to its catalog is, by researchers' accounts, still underway.
The episode is also likely to sharpen a broader argument already underway in the security industry over whether vendors of perimeter security hardware are shipping products fast enough to keep pace with the volume of vulnerabilities being found in them, and whether disclosure timelines that give defenders weeks or months to patch before exploitation begins are shrinking. SOCRadar's analysts noted that the tooling behind the Fortinet campaign, the PivotC2 remote-access trojan, shows signs of having been built with the assistance of AI coding tools, a detail they say is becoming more common in malware they analyze and that, if it holds up, points to attackers matching defenders' own adoption of AI tools to speed up their work. CISA has not said whether it expects to add further vulnerabilities in the same three product families to its catalog in the near term, but the agency's alert accompanying the catalog addition reiterated its standing advice that all organizations, not just those it can compel, adopt risk-based vulnerability management and prioritize remediation of cataloged flaws over routine patching queues.

NASA and IBM release open-source AI trained on 2 million lunar images

Positron AI Raises $875 Million to Challenge Nvidia in Inference Chips

Swedish Physicists Cut Quantum Error Window a Thousandfold in New Control Method
