CISA: U.S. Agencies Must Address Cisco, Citrix, Fortinet Flaws

CISA added three vulnerabilities to its actively exploited catalog, requiring U.S. federal agencies to address them by September 12, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency has set September 12, 2026, as the mandatory deadline for federal agencies to remediate three vulnerabilities added to its catalog of actively exploited vulnerabilities (KEV). The flaws affect Cisco Secure Firewall Management Center, Citrix NetScaler ADC and Gateway, and a Fortinet product, critical network infrastructures present in tens of thousands of corporate environments worldwide.
What Makes This Deadline Different
KEV catalog deadlines are mandatory for U.S. Federal Civil Executive agencies. Noncompliance poses audit risks and, in extreme cases, can lead to cessation of federal funding. The date of September 12 was established by CISA following reports of active exploitation of the three vulnerabilities in the field, including activity detected in honeypots monitored by the agency.
The flaw in Cisco Secure Firewall Management Center, Cisco's centralized firewall management platform used in large corporate and government networks, allows remote access without authentication. In practice, an external attacker can fully compromise an organization's firewall management environment without needing valid credentials. Potential impact includes disabling security rules, creating hidden tunnels, and exfiltrating data. CISA has classified this flaw as critical.
The vulnerability in Citrix NetScaler ADC and Gateway, used for load balancing and secure remote access in hybrid cloud environments, involves authentication bypass with documented active exploitation. Citrix NetScaler is widely utilized by law firms, banks, and healthcare organizations as an external access layer to corporate applications. CISA has recorded attempts at exploitation against vulnerable versions before the alert's publication.
Beyond Federal Agencies: Who Must Act Now
CISA's formal mandate applies only to U.S. Federal Civil Executive agencies, but the inclusion of a vulnerability in the KEV catalog is the most reliable public indicator that exploitation is in progress, not merely theoretical. Private companies operating Cisco FMC or vulnerable versions of Citrix NetScaler face the same risk of active exploitation that motivated the federal deadline.
Managed security service providers operating shared environments for multiple clients face amplified exposure: an unremediated flaw in a central management node can compromise all clients served by the same environment. For these providers, today's deadline represents an emergency patching situation, not a regular cycle.
The Read-Across to Europe and India
In the European Union, the NIS2 Directive, effective since October 2024, imposes essential entities with vulnerability management obligations and a 72-hour notification timeline for significant incidents. There is no equivalent KEV catalog in the U.S., but national cybersecurity agencies, such as Germany's BSI and France's ANSSI, publish their own alerts and often mirror additions to the U.S. KEV with a delay of hours or a few days. European organizations with affected versions of Cisco FMC and Citrix NetScaler should check national bulletins and security notices published by the manufacturers themselves.
In India, delivery centers from consultancies like Infosys, TCS, and Wipro manage infrastructure for global clients, including Cisco and Citrix networks. An unremediated vulnerability in a centralized delivery environment can offer lateral movement to the networks of multiple international corporate clients, making these delivery centers critical exposure points in light of this week's vulnerabilities.
What Security Teams Should Do Now
Cisco and Citrix have published security bulletins with patched versions of their respective products. The documented pattern of active exploitation before the release of patches indicates that threat actors are already in the field. For teams with long patching cycles, the three vulnerabilities in this round justify an emergency process outside of the regular cycle.
Security teams should also check for retroactive indicators of compromise. Given that unauthenticated access on Cisco FMC bypasses credentials, unusual access logs prior to the patch date may reveal intrusions that went unnoticed. SIEM tools should be configured to identify behavioral anomalies in firewall management even after remediation.
CISA had not publicly commented, by the time of this report's closure, on whether the documented exploitation incidents resulted in confirmed compromises of federal agencies.