CISA Sets a Same-Week Deadline for Four Actively Exploited Bugs. One Scores a Perfect 10.
The agency added Cisco, Citrix, Fortinet and Chrome flaws to its known-exploited list this week, giving federal agencies until September 12 to patch three of them.
Meridians Money Desk
Published 13 September 2026 · Updated 13 September 2026 · 4 min read
SoftwareThe short answer
- CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog around September 10, 2026: in Cisco Secure Firewall Management Center, Citrix NetScaler ADC/Gateway, Fortinet FortiOS/FortiSwitchManager, and Google Chromium's V8 engine.
- The Cisco flaw, CVE-2026-20079, scores a maximum 10.0 on the CVSS severity scale and lets an unauthenticated attacker bypass login and reach root-level access.
- Federal civilian agencies had until September 12, 2026 to remediate the Cisco, Citrix and Fortinet flaws.
- The Chrome bug, CVE-2026-87491, is reported as the seventh actively exploited Chrome zero-day logged in 2026 and is fixed in Chrome version 153.0.8010.36 and later.
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog this week, all confirmed as actively exploited. One of them, in a Cisco security appliance, scores the maximum possible severity rating. Federal civilian agencies had until September 12 — the day before this was published — to fix three of the four.
The four vulnerabilities
- CVE-2026-20079 (Cisco Secure Firewall Management Center) — CVSS 10.0. An authentication bypass that lets an unauthenticated remote attacker reach root-level access on the device.
- CVE-2026-19490 (Citrix NetScaler ADC and Gateway) — CVSS 9.3. An authentication bypass affecting devices configured as an AAA virtual server or Gateway, exploitable via a SAML HTTP-Redirect binding flaw.
- CVE-2025-25249 (Fortinet FortiOS, FortiSwitchManager, FortiSASE) — CVSS 8.1. A heap-based buffer overflow allowing unauthenticated remote code execution via crafted packets; reported active exploitation includes deployment of a remote-access trojan called PivotC2.
- CVE-2026-87491 (Google Chromium V8 engine) — CVSS 8.8. An out-of-bounds write exploitable through malicious HTML, allowing arbitrary code execution. Fixed in Chrome 153.0.8010.36 and later.
Who has to fix what, and by when
Per Binding Operational Directive requirements, U.S. federal civilian executive branch agencies had until September 12, 2026 to remediate the Cisco, Citrix and Fortinet vulnerabilities. A separate batch of Windows vulnerabilities added around the same time carries a September 22, 2026 deadline.
If you use Chrome, this affects you directly
The federal directive only binds government agencies, but the Chrome flaw is consumer-facing: it is described as the seventh actively exploited Chrome zero-day catalogued in 2026. Chrome and Chromium-based browsers (Edge, Brave, Opera and others built on the same engine) should be checked and updated to version 153.0.8010.36 or later.
None of this requires action from most home users beyond keeping their browser updated. The Cisco, Citrix and Fortinet flaws affect enterprise network appliances, not consumer products — but they're the kind of infrastructure that, if compromised, sits upstream of services people rely on without knowing it.
Sources
Every factual claim above is traceable to these documents. Check them — that is why they are here.
About this byline
Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.
Sponsored
Paid placement · not editorial
Microsoft's September Patch Fixes Two Windows Flaws Already Under Attack
4 min read · 9 September 2026
Google Confirms Active Attacks Exploiting a Chrome Flaw. Patch Now, Then Check Every Chromium Browser You Use
3 min read · 6 September 2026
Microsoft 365 Outage Knocks Out Outlook and Teams for Hours
3 min read · 1 September 2026
The Meridians Brief
One considered email a week
What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.
Sign-up opens with our launch issue. Nothing is sent or stored yet.
