Skip to content
LIVE

CISA Sets a Same-Week Deadline for Four Actively Exploited Bugs. One Scores a Perfect 10.

The agency added Cisco, Citrix, Fortinet and Chrome flaws to its known-exploited list this week, giving federal agencies until September 12 to patch three of them.

Meridians Money Desk

Published 13 September 2026 · Updated 13 September 2026 · 4 min read

CISA Sets a Same-Week Deadline for Four Actively Exploited Bugs. One Scores a Perfect 10.Software
Photo: Photo by cottonbro studio / Pexels (Pexels License — free to use, no attribution legally required (credited above as good practice).)

The short answer

  • CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog around September 10, 2026: in Cisco Secure Firewall Management Center, Citrix NetScaler ADC/Gateway, Fortinet FortiOS/FortiSwitchManager, and Google Chromium's V8 engine.
  • The Cisco flaw, CVE-2026-20079, scores a maximum 10.0 on the CVSS severity scale and lets an unauthenticated attacker bypass login and reach root-level access.
  • Federal civilian agencies had until September 12, 2026 to remediate the Cisco, Citrix and Fortinet flaws.
  • The Chrome bug, CVE-2026-87491, is reported as the seventh actively exploited Chrome zero-day logged in 2026 and is fixed in Chrome version 153.0.8010.36 and later.

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog this week, all confirmed as actively exploited. One of them, in a Cisco security appliance, scores the maximum possible severity rating. Federal civilian agencies had until September 12 — the day before this was published — to fix three of the four.

The four vulnerabilities

  • CVE-2026-20079 (Cisco Secure Firewall Management Center) — CVSS 10.0. An authentication bypass that lets an unauthenticated remote attacker reach root-level access on the device.
  • CVE-2026-19490 (Citrix NetScaler ADC and Gateway) — CVSS 9.3. An authentication bypass affecting devices configured as an AAA virtual server or Gateway, exploitable via a SAML HTTP-Redirect binding flaw.
  • CVE-2025-25249 (Fortinet FortiOS, FortiSwitchManager, FortiSASE) — CVSS 8.1. A heap-based buffer overflow allowing unauthenticated remote code execution via crafted packets; reported active exploitation includes deployment of a remote-access trojan called PivotC2.
  • CVE-2026-87491 (Google Chromium V8 engine) — CVSS 8.8. An out-of-bounds write exploitable through malicious HTML, allowing arbitrary code execution. Fixed in Chrome 153.0.8010.36 and later.

Who has to fix what, and by when

Per Binding Operational Directive requirements, U.S. federal civilian executive branch agencies had until September 12, 2026 to remediate the Cisco, Citrix and Fortinet vulnerabilities. A separate batch of Windows vulnerabilities added around the same time carries a September 22, 2026 deadline.

If you use Chrome, this affects you directly

The federal directive only binds government agencies, but the Chrome flaw is consumer-facing: it is described as the seventh actively exploited Chrome zero-day catalogued in 2026. Chrome and Chromium-based browsers (Edge, Brave, Opera and others built on the same engine) should be checked and updated to version 153.0.8010.36 or later.

None of this requires action from most home users beyond keeping their browser updated. The Cisco, Citrix and Fortinet flaws affect enterprise network appliances, not consumer products — but they're the kind of infrastructure that, if compromised, sits upstream of services people rely on without knowing it.

Sources

Every factual claim above is traceable to these documents. Check them — that is why they are here.

About this byline

Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.

Sponsored

Paid placement · not editorial

Related reading

The Meridians Brief

One considered email a week

What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.

Sign-up opens with our launch issue. Nothing is sent or stored yet.