CISA Flags Exploited Cisco, Citrix and Fortinet Flaws

What happened
The U.S. Cybersecurity and Infrastructure Security Agency added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, one each affecting Cisco, Citrix, and Fortinet products. Federal Civilian Executive Branch agencies have until September 12, 2026 to apply the fixes. As reported via feeds.feedburner.com, one of the entries, CVE-2026-20079, carries a CVSS score of 10.0 and involves an authentication weakness.
Two things matter about that. First, KEV listings are not theoretical: CISA adds a CVE when there is evidence of real-world exploitation. Second, the federal deadline is two days from today, which tells you how urgently CISA views the risk. If you are a private business, the mandate does not legally bind you, but the threat actors do not check whether your logo is on a .gov domain. We'd encourage you to verify the exact affected product versions and patch guidance directly with each vendor's advisory rather than relying on summaries, including ours, since the specific Citrix and Fortinet CVE identifiers and build numbers determine whether your gear is in scope.

Why this matters for Pittsburgh-area SMBs
Look at the vendor names. Cisco, Citrix, and Fortinet are not exotic enterprise-only brands. They are the firewalls, VPN concentrators, and remote-access gateways sitting at the edge of a huge share of the 10-to-200-employee networks we see across Allegheny, Butler, Washington, and Westmoreland counties. A 35-person CPA firm in Wexford, a machine shop in McKees Rocks, a specialty practice in Shadyside: any of them may well be terminating remote access on hardware covered by one of these advisories.
Edge devices are the worst place to carry an unpatched authentication flaw. They are internet-facing by design, they usually sit outside the segment your endpoint protection watches most closely, and they hold credentials or session tokens that lead straight into the internal network. Ransomware crews have spent years industrializing exactly this path: scan the internet for a vulnerable appliance, authenticate around the login, harvest VPN sessions, move laterally, encrypt on a Friday night. A CVSS 10.0 authentication bypass is the cleanest version of that story.
The compliance consequences land differently depending on your vertical, and they land hard:
- Accounting and financial services. The FTC Safeguards Rule expects you to be identifying and remediating known vulnerabilities on a defined cadence. An exploited CVE sitting unpatched on your firewall while a federal agency publicly flagged it is a documentation problem as much as a security one.
- Healthcare. The HIPAA Security Rule's risk management requirements assume you act on known threats. Unpatched remote access is a textbook finding, and if PHI is exposed you are into breach analysis and notification.
- Defense contractors. CMMC assessments look closely at flaw remediation and boundary protection. If CUI traverses an appliance covered by one of these advisories, this is a scoped asset and your patch timeline needs to be evidenced.
- Legal and professional services. Client audit questionnaires and SOC 2 reviews increasingly ask how quickly you remediate KEV-listed vulnerabilities. "We got to it eventually" is not a good answer in a security review.
The practical trap for smaller organizations is that firewall firmware is nobody's favorite Tuesday task. It often requires a maintenance window, a reboot, and a rollback plan. So it slips. That gap between "patch available" and "patch applied" is precisely the window attackers are working in.
What to do about it this week
- Inventory your edge, today. List every internet-facing appliance: firewalls, VPN gateways, remote-access and virtual-desktop brokers, load balancers. Record vendor, model, current firmware version, and where it is physically or logically deployed. If you cannot produce this list in under an hour, that is finding number one.
- Cross-check against the vendor advisories. Pull Cisco's, Citrix's, and Fortinet's own security bulletins for these CVEs and confirm whether your specific models and builds are affected. Do not assume; confirm the version strings.
- Patch or mitigate on a compressed clock. Treat the September 12 federal deadline as your benchmark rather than someone else's problem. Where an immediate patch is not feasible, apply the vendor's documented workaround and restrict management interface exposure to trusted sources only.
- Assume possible pre-patch compromise. With authentication bypass flaws, patching closes the door but does not evict anyone already inside. Review appliance and VPN logs for unusual admin logins, new local accounts, changed configs, and off-hours sessions from unfamiliar geographies. Rotate admin credentials and invalidate active sessions after patching.
- Turn on MFA everywhere remote access exists. VPN, virtual desktop, and administrative logins. An authentication bypass in the appliance itself is not stopped by MFA, but nearly every follow-on step an attacker takes is.
- Verify your detection coverage. Confirm that EDR or MDR is deployed on every server and workstation, not just most of them, and that appliance logs actually reach somewhere a human or platform reviews them.
- Write down your KEV response process. A short, dated procedure describing who monitors the KEV catalog, how fast you triage, and how patching is evidenced serves double duty as security control and audit artifact. Bring it into your next technology roadmap discussion.
How we help
Our managed IT and patch management practice keeps firmware and endpoint updates on a documented schedule instead of a hopeful one, and our security team monitors KEV additions so client environments get triaged the same week an advisory lands, with evidence you can hand to a HIPAA, SOC 2, CMMC, or FTC Safeguards assessor. If you are not certain who is responsible for your firewall firmware, or whether it is current, that is the conversation to have now.
Call us at 724.888.7007 or reach out through the contact form and we will review your internet-facing devices against the current KEV catalog.
Related reading

Record Microsoft Patch Tuesday: 974 Flaws, Two Zero-Days
Microsoft patched a record 974 vulnerabilities including two exploited Windows zero-days. What Pittsburgh SMBs should verify and patch this week.

Unpatched ScreenConnect Flaw: What Pittsburgh SMBs Should Do
ConnectWise warns of a ScreenConnect remote access flaw with no patch yet. What Pittsburgh SMBs in legal, CPA, healthcare and defense should verify now.

Actively Exploited Chrome Zero-Day: Restart Browsers Today
Google patched an actively exploited Chrome zero-day in the V8 engine plus 11 other flaws. Here is what Pittsburgh SMBs should verify and fix this week.