Our takeCISA added three exploited flaws to its KEV catalog: CVE-2026-20079 (Cisco FMC auth bypass, CVSS 10.0), plus Citrix and Fortinet issues. Federal agencies must patch by Sept. 12; everyone else should treat them as actively weaponized and patch immediately.Cyber Resilience desk
Sources (3)
- hackernews · hackernews
- helpnet · helpnet
- helpnet · helpnet
What this means for you — Security leader:CISA added three actively exploited flaws (Cisco FMC auth bypass CVE-2026-20079, plus Citrix and Fortinet issues) to its KEV catalog. Federal agencies must patch by 12 Sep 2026; treat this as your cue to patch all affected systems immediately and scan for indicators of compromise.
What this means for you — Lean IT orgs:If you run Cisco Secure Firewall Management Center, a Citrix product, or the listed Fortinet gear, apply the vendor patches as soon as possible. Most smaller teams without dedicated security staff should check with your MSP or IT provider today.
What this means for you — MSP:Three new KEV entries (Cisco FMC CVE-2026-20079, plus Citrix and Fortinet flaws) require patching by 12 Sep for any federal clients. Review all managed customers running these products, apply updates, and look for signs of prior exploitation.
What this means for you — Researcher:CISA added CVE-2026-20079 (Cisco FMC auth bypass) and two other flaws to the KEV catalog after confirmed in-the-wild exploitation by nation-state and ransomware actors.