Cisco’s Secure Firewall Management Center has a 10.0. CVE-2026-20079. Auth bypass. No creds needed. You get root. CISA put it in KEV, feds had until Sept 12 to patch. That deadline is gone. If you run FMC, check your version now. Not Monday. Now.
Sep 24, 2026 · 12:20 PM UTC
1
3
4
831
Citrix NetScaler CVE-2026-19490 is getting hit too. Honeypots saw 56 attempts since early Sept. 36 on Sept 8 alone. Auth bypass in ADC/Gateway when it’s set up as AAA vserver or Gateway. CVSS 9.3. If that’s your config, don’t sit on it.
1
2
6
1,013
Fortinet CVE-2025-25249 is being used to drop PivotC2 RAT. Hits FortiOS, FortiSwitchManager, FortiSASE. 3,000+ IPs targeted, 178 devices infected, mostly US. The annoying part? These are firewalls and gateways. The stuff you buy to keep attackers out is the way in. Patch and hunt. #infosec
2
1
5
340
