The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three critical flaws affecting enterprise hardware and software from Cisco, Citrix, and Fortinet. This designation signifies that the vulnerabilities are currently being exploited in the wild, posing an immediate risk to organizational security. Federal Civilian Executive Branch (FCEB) agencies are now required to remediate these specific security gaps by a strict deadline of September 12, 2026.
One of the most significant additions is identified as CVE-2026-20079, which carries a maximum CVSS severity score of 10.0. This particular vulnerability relates to an authentication issue, though specific technical details regarding the exploitation methods for the Cisco and Fortinet flaws were categorized alongside the Citrix vulnerability in the agency's Wednesday update. CISA typically adds vulnerabilities to this list when there is clear evidence of active exploitation, regardless of whether the targets are government or private sector entities.
For IT directors and operations leaders, this federal directive serves as a high priority signal for vulnerability management workflows. While the CISA mandate legally applies to federal agencies, the inclusion of these specific Cisco, Citrix, and Fortinet flaws in the KEV catalog indicates that all organizations using these products should prioritize these updates to prevent potential unauthorized access or system compromise.
The BroadVision view
This CISA directive highlights the necessity of rapid patch deployment for core networking and infrastructure components. Mid-market IT teams should treat the KEV catalog as a baseline for emergency maintenance windows to mitigate active threats. Consistent monitoring of vendor security advisories ensures that critical systems remain protected against known exploits. Explore our strategic IT services for guidance on infrastructure security.
