Executive Summary
In September 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The vulnerabilities affect widely deployed enterprise infrastructure including Fortinet security appliances (CVE-2025-25249 heap-based buffer overflow), Citrix NetScaler (CVE-2026-19490 authentication bypass), Google Chromium V8 engine (CVE-2026-87491 out-of-bounds write), and Cisco Firewall Management Center (CVE-2026-20079 authentication bypass). These vulnerabilities pose significant risks as they target critical network security infrastructure and web browsers used across federal and private sector environments.
This incident highlights the ongoing threat landscape where attackers systematically target network security appliances and widely-used software components to establish persistent access and bypass security controls, reflecting the continued evolution of threat actor tactics toward infrastructure-level compromises.
Why This Matters Now
The addition of these four vulnerabilities to CISA's KEV Catalog represents an immediate security imperative as they affect core network infrastructure components with active exploitation evidence, requiring urgent patching under federal BOD 26-04 mandates and highlighting critical gaps in enterprise security infrastructure protection.
Attack Path Analysis
Attackers exploited known vulnerabilities in Fortinet, Citrix NetScaler, Google Chromium, and Cisco Firewall Management Center to gain initial access through authentication bypass and buffer overflow techniques. They escalated privileges using compromised management systems, moved laterally through unencrypted east-west traffic, established command and control through unfiltered egress channels, and exfiltrated sensitive data while maintaining persistence across hybrid cloud environments.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of CVE-2025-25249 (Fortinet heap buffer overflow), CVE-2026-19490 (Citrix NetScaler auth bypass), CVE-2026-87491 (Chrome V8 out-of-bounds write), and CVE-2026-20079 (Cisco FMC auth bypass) to gain unauthorized access to network infrastructure and management systems
Related CVEs
CVE-2025-25249
CVSS 9.8A heap-based buffer overflow vulnerability in Fortinet multiple products allows an unauthenticated remote attacker to execute arbitrary code.
Affected Products:
Fortinet FortiOS – < 7.4.2, < 7.2.6, < 7.0.13
Fortinet FortiProxy – < 7.4.1, < 7.2.7
Exploit Status:
exploited in the wildCVE-2026-19490
CVSS 9.8An authentication bypass vulnerability in Citrix NetScaler allows an unauthenticated remote attacker to bypass authentication using an alternate path or channel.
Affected Products:
Citrix NetScaler ADC – < 14.1-17.102, < 13.1-49.15
Citrix NetScaler Gateway – < 14.1-17.102, < 13.1-49.15
Exploit Status:
exploited in the wildCVE-2026-87491
CVSS 8.8An out-of-bounds write vulnerability in Google Chromium V8 JavaScript engine allows a remote attacker to potentially exploit heap corruption.
Affected Products:
Google Chrome – < 118.0.5993.117
Microsoft Edge (Chromium-based) – < 118.0.2088.76
Exploit Status:
exploited in the wildCVE-2026-20079
CVSS 10An authentication bypass vulnerability in Cisco Firewall Management Center allows an unauthenticated remote attacker to bypass authentication using an alternate path or channel.
Affected Products:
Cisco Firewall Management Center – < 7.4.1, < 7.2.6, < 7.0.5
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Valid Accounts
Abuse Elevation Control Mechanism
Impair Defenses: Disable or Modify Tools
Exploitation for Client Execution
Process Injection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ZTMM-IA-01
PCI DSS 4.0 – Vulnerability Management Program
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.08
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical exposure to authentication bypass vulnerabilities in Citrix NetScaler and Cisco Firewall Management Center requiring immediate KEV remediation.
Financial Services
Banking infrastructure using Fortinet security appliances and Cisco firewall management systems vulnerable to heap overflow and authentication bypass exploits.
Health Care / Life Sciences
Healthcare networks utilizing affected Fortinet, Citrix, and Cisco products risk HIPAA compliance violations through authentication bypass and buffer overflow attacks.
Information Technology/IT
IT service providers managing enterprise security infrastructure face significant client exposure through Chromium V8 exploits and network appliance vulnerabilities.
Sources
- CISA Adds Four Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalogVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Binding Operational Directive 26-04: Prioritizing Security Updates Based on Riskhttps://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-riskVerified
- National Vulnerability Databasehttps://nvd.nist.gov/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this multi-vector attack by implementing microsegmentation, encrypted east-west traffic, and controlled egress policies that limit lateral movement and reduce the overall blast radius across hybrid cloud environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric would likely have limited the scope of initial compromise by enforcing identity-aware access controls and reducing the attack surface available to unauthenticated exploitation attempts against management interfaces.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have constrained privilege escalation by isolating management systems and limiting cross-system administrative access even when individual appliances become compromised.
Control: East-West Traffic Security
Mitigation: Encrypted microsegmentation would likely have significantly limited lateral movement by enforcing cryptographic isolation between network segments and restricting unauthorized pivoting across compromised infrastructure boundaries.
Control: Multicloud Visibility & Control
Mitigation: Comprehensive traffic visibility and behavioral analysis would likely have detected anomalous communication patterns from compromised management systems and enabled rapid identification of unauthorized command and control channels.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have constrained data exfiltration by enforcing strict outbound traffic controls and preventing unauthorized data transmission from compromised infrastructure components.
Residual impact would likely be limited to initially compromised segments with reduced blast radius and constrained ability to affect business-critical operations across the broader hybrid cloud environment.
Impact at a Glance
Affected Business Functions
- Federal Government Operations
- Critical Infrastructure Services
- Public-facing Web Applications
- Network Security Management
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized access to sensitive government systems and data through exploitation of authentication bypass and buffer overflow vulnerabilities in critical network infrastructure components.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS (Suricata) with updated signatures to detect and block exploitation attempts against known CVEs in network appliances and management systems
- • Deploy Zero Trust Segmentation with microsegmentation controls to prevent lateral movement even when perimeter security appliances are compromised
- • Enable Encrypted Traffic (HPE) with MACsec and IPsec for all east-west traffic to prevent interception of sensitive data during lateral movement
- • Establish Egress Security & Policy Enforcement to detect and block unauthorized command and control communications from compromised infrastructure components
- • Deploy Multicloud Visibility & Control with centralized monitoring to detect anomalous behavior and policy violations across hybrid cloud network infrastructure



