CISA KEV Catalog Update: Fortinet, Citrix NetScaler, Chromium V8, and Cisco FMC Actively Exploited Vulnerabilities
First seen Sep 10, 2026 · Updated Sep 10, 2026
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Fortinet products, Citrix NetScaler, Google Chromium V8, and Cisco Firewall Management Center. These vulnerabilities include authentication bypass and memory corruption flaws that grant attackers significant post-exploitation control, and federal agencies are required under BOD 26-04 to remediate them on an accelerated timeline.
Technical Analysis
CVE-2025-25249 is a heap-based buffer overflow in Fortinet products that can lead to memory corruption and potential code execution. CVE-2026-19490 and CVE-2026-20079 are authentication bypass vulnerabilities using an alternate path or channel in Citrix NetScaler and Cisco Firewall Management Center respectively, allowing attackers to bypass authentication controls on perimeter security devices. CVE-2026-87491 is an out-of-bounds write vulnerability in Google Chromium's V8 JavaScript engine, which can be exploited via malicious web content to achieve memory corruption and potentially remote code execution in the browser sandbox. Given that these products (Fortinet gateways, Citrix NetScaler, Cisco FMC, and Chromium-based browsers) are commonly deployed as network perimeter defenses and management interfaces for infrastructure hosting AI agent frameworks and RAG pipelines, successful exploitation could grant attackers a foothold to intercept API keys, exfiltrate credentials used by agent tool-calling systems, or pivot into environments running LLM orchestration tools; browser-based V8 exploitation is particularly relevant for agent systems that use headless Chromium instances for web browsing/automation tasks.
Affected Systems
Fortinet multiple products (version details per Fortinet advisory for CVE-2025-25249); Citrix NetScaler ADC/Gateway (affected versions per Citrix advisory for CVE-2026-19490); Google Chromium-based browsers including Chrome (versions prior to patched release for CVE-2026-87491); Cisco Firewall Management Center (affected versions per Cisco advisory for CVE-2026-20079)
Indicators of Compromise
- No specific IOCs published in this CISA alert; organizations should consult vendor advisories (Fortinet PSIRT, Citrix Security Bulletins, Google Chrome Releases, Cisco Security Advisories) for detection signatures and exploitation indicators
Remediation Steps
- 1
Apply vendor patches immediately
Update Fortinet products, Citrix NetScaler, Chromium/Chrome, and Cisco Firewall Management Center to the latest patched versions addressing CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, and CVE-2026-20079.
- 2
Comply with BOD 26-04 timelines
FCEB agencies must remediate these KEV-listed vulnerabilities within CISA-mandated deadlines, prioritizing publicly exposed assets that grant total control post-exploitation.
- 3
Check for prior compromise
Per BOD 26-04, verify whether systems were compromised before patches were applied by reviewing logs, authentication events, and configuration changes on affected devices.
- 4
Restrict management interface exposure
Limit public internet exposure of Citrix NetScaler, Cisco FMC, and Fortinet management interfaces; enforce network segmentation and VPN/MFA access controls.
- 5
Update browser fleets
Ensure all Chromium-based browsers, including those used in automated or headless agent workflows, are updated to patched versions to mitigate V8 exploitation risk.
- 6
Monitor for exploitation indicators
Deploy detection rules based on vendor advisories and threat intelligence feeds to identify exploitation attempts against these four CVEs.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.