On 9 September 2026 the US Cybersecurity and Infrastructure Security Agency (CISA) added three flaws to its Known Exploited Vulnerabilities (KEV) catalog — one each in Cisco, Citrix and Fortinet products — and gave federal agencies until 12 September to patch. All three sit in the same place: the internet-facing edge of the network, on the very devices meant to keep attackers out.

Quick answer: Three perimeter products are confirmed under active attack — Cisco Secure Firewall Management Center (CVE-2026-20079, CVSS 10.0), Citrix NetScaler ADC/Gateway (CVE-2026-19490, CVSS 9.3) and Fortinet FortiOS/FortiSwitchManager/FortiSASE (CVE-2025-25249, CVSS 7.3). The CISA deadline binds only US federal agencies, but the exploitation is global. If your business runs any of these at the edge, check your firmware version this week, patch, and — if the device was exposed and unpatched — assume it may already have been touched.

What was added, and why it matters

The three entries, per CISA and the respective vendor advisories:

  • CVE-2026-20079 — Cisco Secure Firewall Management Center (CVSS 10.0). An authentication bypass in the web interface that lets an unauthenticated remote attacker execute script files and obtain root on the underlying OS. Cisco updated its advisory to confirm it became aware of active exploitation in August 2026, and says it identified three clusters of post-compromise activity on FMC instances deploying web shells and malware. Cisco has stated there are no workarounds, and that hot fixes will not remediate a device that is already compromised.
  • CVE-2026-19490 — Citrix NetScaler ADC and NetScaler Gateway (CVSS 9.3). An authentication bypass that applies when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN or RDP Proxy) — in other words, precisely the remote-access configurations most businesses run.
  • CVE-2025-25249 — Fortinet FortiOS, FortiSwitchManager and FortiSASE (CVSS 7.3). A heap-based buffer overflow allowing a remote unauthenticated attacker to execute arbitrary code or commands via crafted requests. SOCRadar has reported a campaign weaponising this flaw to deliver a Node.js remote access trojan called PivotC2, with interactive shells, SOCKS5/HTTP proxy tunnelling, network scanning and FortiGate-specific configuration harvesting and credential decryption.

Note the CVSS scores are not the story. The FortiOS flaw scores 7.3 — a "high", not a "critical" — and would sit mid-list in most patch queues. It is on the KEV catalog anyway, because it is being used right now. Exploitation status beats severity score as a patching signal.

The pattern: your perimeter is the target

Firewalls, VPN gateways and management consoles are attractive precisely because of what they are. They are internet-facing by design, they hold credentials and configuration for the rest of the network, and — in most Indian SMEs and mid-market companies — nobody is watching their logs. As SOCRadar's findings suggest, attackers scan continuously for exposed edge devices to gain initial access, taking advantage of their lack of robust monitoring or telemetry.

There is a second uncomfortable detail in the Cisco case. The company first disclosed CVE-2026-20079 in March 2026 with no evidence of exploitation. Exploitation began months later. Any organisation that read the March advisory, saw "not exploited", and deferred the upgrade was exposed by August. A patch decision made once, on day-one information, is not a decision that stays correct.

What Indian businesses should do this week

None of this requires a big security budget. It requires knowing what you have and acting on a short list:

  • Inventory every internet-facing device. Firewalls, VPN concentrators, management consoles, load balancers, NAS boxes, IP cameras and DVRs. Record model, firmware version and who owns the upgrade. Most Indian businesses we assess cannot produce this list on demand — and you cannot patch what you have not counted.
  • Check your versions against the vendor advisories. Cisco, Citrix and Fortinet each publish fixed-release tables. If you are on a Cisco Secure FMC, a NetScaler in Gateway/AAA mode, or a FortiGate running an affected FortiOS branch, this is a this-week job, not a next-quarter job.
  • Never expose management interfaces to the internet. Firewall and appliance admin portals should be reachable only from an internal management VLAN or over VPN with MFA. This one control would have blunted two of these three flaws.
  • Treat "exposed and unpatched" as "possibly compromised". If a device sat vulnerable during the exploitation window, patching alone is not closure. Hunt for web shells and unfamiliar accounts, rotate every credential and certificate stored on the appliance, and diff the configuration against a known-good backup.
  • Subscribe to the feeds that matter. The CISA KEV catalog is free and CERT-In issues India-specific advisories. Between them you get a prioritised, evidence-based patch list at no cost.
  • Check that your support contract is actually live. An expired UTM or firmware-entitlement subscription means no firmware updates — a surprisingly common reason Indian businesses stay unpatched. If you are not sure, our license renewals team can check your entitlement status in a day.

Where a partner helps

Patching a perimeter firewall is not the same as updating a laptop. It needs a maintenance window, a tested rollback, HA-pair sequencing so the business stays online, and a configuration review afterwards. That is the work we do every week.

As an authorized dealer for Fortinet, Sophos, Cisco, Palo Alto, Checkpoint, Juniper and SonicWall, Invitty handles firmware upgrades and migrations across Chennai, Bangalore, Hyderabad, Coimbatore, Kochi and the rest of South India — see our firewall and SASE practices. If you would rather find out what is exposed before an attacker does, our VAPT team runs external perimeter assessments that map every internet-facing service, flag unpatched versions and exposed management interfaces, and hand you a fix list in priority order. For businesses that need this monitored continuously rather than annually, GRC & compliance and ISO 27001 programmes build patch management into a documented process.

Frequently asked questions

Which vulnerabilities did CISA add to the KEV catalog in September 2026?

CISA added three actively exploited flaws on 9 September 2026: CVE-2026-20079 (CVSS 10.0), an authentication bypass in Cisco Secure Firewall Management Center; CVE-2026-19490 (CVSS 9.3), an authentication bypass in Citrix NetScaler ADC and Gateway; and CVE-2025-25249 (CVSS 7.3), a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager and FortiSASE. US federal agencies were required to patch by 12 September 2026.

Does the CISA KEV deadline apply to Indian companies?

No — the deadline binds only US federal civilian agencies. But the KEV catalog is a public list of flaws confirmed to be exploited in the wild, which makes it one of the best free patch-priority feeds available to any Indian business. Attackers scan the whole internet, not just US networks.

How do I know if my firewall or VPN appliance is affected?

Check the exact model and firmware version of every internet-facing appliance against the vendor advisory — Cisco, Citrix and Fortinet all publish fixed-release tables. If you do not have a current inventory of your edge devices and their firmware, building that list is step one.

What if a device was already compromised before we patched?

Patching does not undo a breach. Cisco has warned that hot fixes do not remediate devices already compromised via CVE-2026-20079. If an appliance was exposed and unpatched during the exploitation window, treat it as suspect: hunt for web shells and unexpected accounts, rotate all credentials and certificates stored on it, and review the configuration for unauthorised changes.

Can Invitty help with firewall patching and edge-device review in Chennai?

Yes. As an authorized partner for Fortinet, Sophos, Cisco, Palo Alto, Checkpoint, Juniper and SonicWall, we handle firmware upgrades, HA-pair patching with planned cutovers, management-interface hardening and license renewals across Chennai, Bangalore, Hyderabad, Coimbatore, Kochi and the rest of South India. Our VAPT team can also run an external exposure review of your perimeter.

Get your perimeter checked — Chennai & South India

If you are not certain what firmware your firewall is running, or whether its management interface is reachable from the internet, that uncertainty is the finding. Talk to Invitty's certified engineers for a free perimeter review — we will check your edge devices against current advisories, confirm your license entitlements are live, and give you a prioritised patch plan with a same-day GST quote if hardware or renewals are needed. You may also want to read our guide on how to choose the right firewall for your business.

This article summarises publicly reported information as of 14 September 2026, drawn from CISA's Known Exploited Vulnerabilities catalog advisory of 9 September 2026, Cisco's security advisory for CVE-2026-20079, Fortinet PSIRT advisory FG-IR-25-084, Citrix's advisory for CVE-2026-19490, and reporting by The Hacker News and SOCRadar. CVSS scores and affected-version details should be verified against the vendor advisory for your specific product and release before acting. Invitty is not affiliated with, endorsed by, or speaking on behalf of CISA, Cisco, Citrix or Fortinet.