Our takeCISA added four vulnerabilities to its KEV catalog: CVE-2025-25249 (Fortinet heap-based buffer overflow), CVE-2026-19490 (Citrix NetScaler auth bypass), CVE-2026-87491 (Chromium V8 out-of-bounds write), and one more. All are confirmed exploited in the wild. Patch them now.Cyber Resilience desk
Sources (2)
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA added four vulnerabilities to its KEV catalog: CVE-2025-25249 (Fortinet heap-based buffer overflow), CVE-2026-19490 (Citrix NetScaler authentication bypass), CVE-2026-87491 (Chromium V8 out-of-bounds write), and one additional. All are confirmed exploited in the wild. Patch immediately where present.
What this means for you — Lean IT orgs:CISA added four vulnerabilities to its KEV catalog; they are confirmed exploited in the wild. Update Fortinet, Citrix NetScaler, and Chrome immediately if you run any of them.
What this means for you — MSP:CISA added four vulnerabilities (including Fortinet, Citrix NetScaler, and Chromium) to its KEV catalog; all are confirmed exploited in the wild. Review client estates for these products and ensure patching is current.
What this means for you — Researcher:CISA added four actively exploited vulnerabilities to the KEV catalog: CVE-2025-25249 (Fortinet), CVE-2026-19490 (Citrix NetScaler), CVE-2026-87491 (Chromium V8), plus one more. Confirmed in-the-wild exploitation.