The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog. This action triggers a binding deadline of September 12, 2026, for all Federal Civilian Executive Branch (FCEB) agencies to apply patches or mitigations.

Three Critical Flaws Under Active Attack

According to The Hacker News, the newly catalogued vulnerabilities include a Cisco authentication bypass flaw tracked as CVE-2026-20079, carrying a maximum CVSS severity score of 10.0. Additional flaws affecting Citrix and Fortinet products were also added to the KEV list. All three products — Cisco networking equipment, Citrix virtualization platforms, and Fortinet security appliances — are foundational to enterprise and government networks worldwide.

CISA's inclusion of these flaws in the KEV catalog is based on evidence of real-world exploitation, not theoretical risk. Each entry reflects credible intelligence that threat actors are already leveraging the flaws in active attacks.

What the KEV Mandate Entails

Under Binding Operational Directive (BOD) 22-01, CISA has the authority to require federal agencies to remediate specific vulnerabilities within defined timeframes. Inclusion in the KEV catalog is not advisory — it is a legal compliance obligation for FCEB agencies. Organizations that fail to meet the September 12 deadline risk falling out of compliance with federal cybersecurity mandates.

Implications Extend Globally Beyond U.S. Agencies

While the directive's legal force applies only to U.S. federal civilian agencies, the implications reach far beyond that scope. Cisco, Citrix, and Fortinet products are deployed across enterprises, critical infrastructure operators, managed service providers, and government entities globally.

For IT and security teams worldwide, CISA's KEV catalog has become a de facto prioritization tool. When the agency flags a vulnerability as actively exploited, it signals that all organizations should evaluate their exposure and move to patch or mitigate immediately, regardless of whether they are subject to BOD 22-01. The Cisco flaw's maximum CVSS score of 10.0 suggests that attackers can gain unauthorized access to affected systems without valid credentials — a scenario that could lead to full network compromise if left unaddressed.

Urgent Steps for Organizations

All entities running Cisco, Citrix, or Fortinet infrastructure should take immediate action:

  • Conduct an emergency inventory to identify all instances of affected products across the network.
  • Apply vendor-supplied patches or mitigations with high priority, prioritizing systems exposed to the internet.
  • Initiate forensic log review to detect potential signs of compromise associated with these vulnerabilities.
  • Monitor CISA's KEV catalog for updates, including any additional CVE identifiers or revised guidance.

The September 12 deadline is imminent. With the compliance window closing rapidly for federal agencies, the message is clear: patch now or risk exposure to threat actors who are already exploiting these flaws in active campaigns.


美國網絡安全和基礎設施安全局(CISA)已將三項影響 Cisco、Citrix 及 Fortinet 產品的積極利用漏洞納入其「已知被利用漏洞」(KEV)目錄。此舉觸發了具有約束力的期限,要求所有聯邦民事行政部門(FCEB)機構須於 2026 年 9 月 12 日前應用補丁或緩解措施。

三項正遭積極攻擊的關鍵缺陷

據 The Hacker News 報導,新加入目錄的漏洞包括編號為 CVE-2026-20079 的 Cisco 身份驗證繞過漏洞,其 CVSS 嚴重性評分達滿分 10.0。影響 Citrix 和 Fortinet 產品的其他缺陷也被加入 KEV 名單。這三類產品——Cisco 網絡設備、Citrix 虛擬化平台及 Fortinet 安全設備——是全球企業及政府網絡的基礎設施。

CISA 將這些缺陷納入 KEV 目錄,是基於其在現實世界中被利用的證據,而非理論風險。每一項記錄均反映出可靠的威脅情報,表明威脅行為者正積極利用這些缺陷發動攻擊。

KEV 強制令的具體要求

根據《具有約束力的操作指令》(BOD)22-01,CISA 有權要求聯邦機構在指定時段內補救特定漏洞。納入 KEV 目錄並非建議性質——對 FCEB 機構而言,這是一項法律合規義務。未能滿足 9 月 12 日期限的組織,將面臨違反聯邦網絡安全指令的風險。

影響範圍超越美國機構,波及全球

儘管該指令的法律效力僅適用於美國聯邦民事機構,但其影響遠超此範圍。Cisco、Citrix 及 Fortinet 的產品在全球範圍內的企業、關鍵基礎設施營運商、託管服務供應商及政府機構中廣泛部署。

對於全球各地的 IT 和安全團隊而言,CISA 的 KEV 目錄已成為事實上的優先級別評估工具。當該機構標誌某漏洞為積極利用時,即表明所有組織,無論是否受 BOD 22-01 約束,都應評估自身暴露風險並立即著手修補或緩解。Cisco 漏洞的 CVSS 最高評分 10.0 表明,攻擊者可能在無有效憑證的情況下獲取對受影響系統的未授權存取——若不加以處理,可能導致網絡被全面入侵。

組織的緊急應對步驟

所有運行 Cisco、Citrix 或 Fortinet 基礎設施的實體應立即採取行動:

  • 進行緊急清點,識別網絡中所有受影響產品實例。
  • 優先應用廠商提供的補丁或緩解措施,尤其針對暴露於互聯網的系統。
  • 啟動取證日誌審查,偵測與這些漏洞相關的潛在入侵跡象。
  • 持續關注 CISA 的 KEV 目錄,獲取更新資訊,包括任何額外的 CVE 識別碼或修訂指引。

9 月 12 日期限迫在眉睫。隨著聯邦機構的合規窗口迅速關閉,訊息明確無誤:立即修補,否則將面臨已積極利用這些漏洞發動攻擊的威脅行為者的風險。

新聞來源 / Original News Source