Threat Brief — 2026-09-10 — Four CVEs Hit CISA KEV
CISA's Known Exploited Vulnerabilities catalog absorbed four high-severity CVEs today, spanning Cisco, Google Chrome, Fortinet, and Citrix NetScaler products. Two of these—Cisco Secure FMC and Chrome V8—were already reported as actively exploited yesterday; their KEV listing now binds federal agencies to remediation deadlines and confirms exploitation is broad enough to warrant catalog entry. The Fortinet and Citrix entries represent newly confirmed in-the-wild exploitation via their KEV addition.
Top items
- CVE-2026-20079KEV — Cisco Secure FMC authentication bypass added to CISA KEV. This max-severity authentication-bypass flaw in Cisco Secure Firewall Management Center and Security Cloud Control Firewall Management is confirmed exploited in the wild. Active exploitation was first reported 2026-09-09 by BleepingComputer; CISA has now formally added it to the KEV catalog. (src: CISA KEV; first reported 2026-09-09 by BleepingComputer)
- Three additional CVEs added to CISA KEV — Chrome V8, Fortinet, and Citrix NetScaler. CISA confirmed exploitation in the wild for CVE-2026-87491KEV (Google Chromium V8 out-of-bounds write allowing arbitrary code execution inside the sandbox via a crafted HTML page), CVE-2025-25249KEV (Fortinet FortiOS, FortiSwitchManager, and FortiSASE heap-based buffer overflow enabling unauthorized code execution), and CVE-2026-19490KEV (Citrix NetScaler ADC and Gateway authentication bypass via an alternate path or channel). The Chrome V8 zero-day was first reported as actively exploited on 2026-09-09 by BleepingComputer. These KEV additions are part of an ongoing catalog-update story first reported 2026-08-17 by CISA. (src: CISA KEV; Chrome V8 first reported 2026-09-09 by BleepingComputer; KEV story first reported 2026-08-17 by CISA)
- Dark Reading: vulnerability discovery outpaces human remediation capacity. An analysis of Project Glasswing findings shows only a fraction of discovered vulnerabilities have reached disclosure, and an even smaller number have been fixed—highlighting a widening gap between automated vulnerability discovery and the human bandwidth available to triage and patch. (src: Dark Reading)
Themes
Three of today's four KEV additions target network-perimeter devices—Cisco FMC, Fortinet, and Citrix NetScaler—products that are typically internet-facing and serve as gateways to internal networks. This concentration reinforces how attackers prioritise externally reachable infrastructure for initial access, and why edge-device vulnerabilities carry disproportionate operational risk.
