← All briefings

Cisco Secure Firewall Management Center / Security Cloud Control · Citrix NetScaler ADC / Gateway · Fortinet FortiOS

Date: 2026-09-10 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

CISA added four vulnerabilities to the KEV Catalog, including actively exploited Cisco Secure Firewall Management Center, Citrix NetScaler, Fortinet and Chromium flaws. Cisco exploitation is confirmed across ransomware- and state-linked clusters. A separate campaign used hundreds of AI agents to compromise at least 395 PaperCut servers. European defenders should also prioritize emergency Check Point VPN updates, which address two unauthenticated remote-code-execution vulnerabilities affecting remote-access and site-to-site VPN deployments.

Critical Vulnerabilities

CVE-2026-20079 — Cisco Secure Firewall Management Center / Security Cloud Control

  • Severity: CVSS 10.0
  • EPSS: Not supplied
  • Technical detail: An authentication-bypass vulnerability allows an unauthenticated remote attacker to execute script files and obtain root access to the underlying operating system. The issue affects Cisco Secure Firewall Management Center and Security Cloud Control firewall-management deployments.
  • Exploitation status: STATUS CHANGE — actively exploited. Cisco confirmed exploitation, and reporting links activity to multiple ransomware and state-sponsored threat clusters.
  • Remediation: Apply Cisco’s security updates immediately. Restrict management interfaces to trusted administrative networks, review administrator logins and configuration changes, and investigate unexpected scripts, root-level activity or outbound connections.

CVE-2026-19490 — Citrix NetScaler ADC / Gateway

  • Severity: Not supplied; CISA KEV-listed
  • EPSS: Not supplied
  • Technical detail: An authentication-bypass vulnerability involving an alternate path or channel can allow an unauthenticated remote attacker to bypass authentication. Exposure is relevant where NetScaler is configured as an AAA virtual server or Gateway for SSL VPN, ICA Proxy, CVPN or RDP Proxy.
  • Exploitation status: STATUS CHANGE — added to CISA KEV. The prior report noted attacks; CISA now requires remediation by 2026-09-12.
  • Remediation: Apply the vendor fix immediately and prioritize internet-facing appliances. Review VPN and administrative authentication logs, session activity, configuration changes and possible post-authentication access.

CVE-2025-25249 — Fortinet FortiOS, FortiSwitchManager and FortiSASE

  • Severity: Not supplied; CISA KEV-listed
  • EPSS: Not supplied
  • Technical detail: A heap-based buffer overflow can permit unauthorized code or command execution through specially crafted packets. Impact depends on the affected Fortinet product and exposed network services.
  • Exploitation status: NEW — added to CISA KEV with a remediation deadline of 2026-09-12. The supplied data does not identify a specific campaign or ransomware use.
  • Remediation: Apply Fortinet updates immediately, restrict management and exposed service interfaces, and review device logs for malformed requests, unexpected administrative activity, configuration changes and new accounts.

CVE-2026-87491 — Chromium V8

  • Severity: Not supplied; CISA KEV-listed
  • EPSS: Not supplied
  • Technical detail: An out-of-bounds write in the V8 JavaScript engine can enable arbitrary code execution inside the browser sandbox through a crafted HTML page. Affected Chromium-based browsers may include Google Chrome, Microsoft Edge and Opera.
  • Exploitation status: NEW — added to CISA KEV. CISA remediation is due by 2026-09-23.
  • Remediation: Accelerate browser updates across managed endpoints and verify version compliance. Prioritize privileged-user workstations, enforce browser auto-update controls and investigate suspicious browser crashes, downloads or exploit-like activity.

CVE-2026-57967 — Apache ActiveMQ Artemis

  • Severity: CVSS 9.8
  • EPSS: 0 — no EPSS exploitation probability currently reported
  • Technical detail: An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing authenticated session and assume its execution context. The issue affects Apache ActiveMQ Artemis and Apache Artemis versions within the reported vulnerable ranges.
  • Exploitation status: NEW — published 2026-09-10. No exploitation has been reported in the supplied data.
  • Remediation: Upgrade to the vendor-fixed release when available, restrict broker protocol access to trusted networks and review session, authentication and administrative activity. Treat internet-exposed brokers as a priority.

ONGOING

  • CVE-2026-75650 (Adobe Commerce/Magento): actively exploited in StyleSmuggler; patch immediately and complete web-shell and payment-file hunting.
  • CVE-2026-86218 (N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later and audit management actions.
  • CVE-2026-81963 / CVE-2026-85880 (Windows): actively exploited; deploy September updates.
  • CVE-2026-63520 (Microsoft SharePoint): exploitation and public PoC remain reported; verify patching and hunt for web shells.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut): exploitation remains reported; remediate before the 2026-09-14 deadline.

European Advisories

CERT-EU advisory 2026-012 covers two critical Check Point vulnerabilities affecting Security Gateway, Security Management Server and Spark Firewall deployments using Remote Access VPN or Site-to-Site VPN. Both are rated CVSS 9.8 and may allow unauthenticated remote code execution under specific conditions. Apply the emergency hotfixes immediately and restrict VPN exposure while deployment is pending.

WID-SEC-2026-0610 (Cisco Secure Firewall Management Center): covered in Critical Vulnerabilities.

WID-SEC-2026-3286 is a new critical Budibase advisory covering privilege escalation, security-control bypass, SQL injection and data exposure or manipulation. Review deployment exposure and apply vendor fixes.

CERT-Bund updates cover Kemp LoadMaster, Samba, Linux Kernel, BIND, Firefox/Thunderbird, Red Hat Enterprise Linux, NGINX, Apache HTTP Server, Node.js, QEMU and other widely deployed components. Validate applicability and complete pending updates, prioritizing internet-facing, identity, VPN and administrative systems.

Active Threats and Campaigns

  • PaperCut exploitation — STATUS CHANGE: Reporting indicates a likely Russian-speaking actor used hundreds of AI agents to develop and launch exploits against PaperCut NG/MF, compromising at least 395 organizations. Patch CVE-2026-81578 and CVE-2026-82078, identify exposed servers and hunt for new accounts, web shells, command execution and unusual outbound traffic.
  • Cisco FMC exploitation — STATUS CHANGE: Cisco Talos-linked reporting describes exploitation by ransomware and state-sponsored clusters. Treat exposed FMC management interfaces as potentially compromised and perform retrospective authentication and configuration review.
  • BlueMoon exploit kit — NEW: Multiple cyber-espionage groups reportedly used an exploit kit targeting Windows and Chrome zero-days. The supplied data provides no CVE identifiers or IOCs; ensure Windows and browser updates are current and monitor exploit-like browser crashes and suspicious child processes.
  • Magento StyleSmuggler — ONGOING: Active exploitation continues; perform compromise hunting after patching.

Security News and Context

  1. Patch Cisco FMC/SCC, Citrix NetScaler and Fortinet systems immediately; complete CISA KEV deadlines.
  2. Apply Check Point emergency VPN hotfixes and restrict gateway management access.
  3. Update Chrome, Edge and other Chromium-based browsers across managed endpoints.
  4. Patch Apache ActiveMQ Artemis and restrict broker protocols to trusted networks.
  5. Remediate PaperCut and investigate for AI-assisted exploitation indicators.
  6. Hunt Cisco, Citrix, Fortinet and Magento systems for unauthorized accounts, configuration changes, web shells and suspicious outbound activity.
  7. Audit internet-facing LiteLLM gateways for default keys and rotate all exposed credentials.
  8. Continue remediation of previously reported items: N-central, Windows KEV flaws, SharePoint, MikroTik RouterOS, Citrix NetScaler, PaperCut, Chromium V8, SonicWall SMA1000 and Langflow.