OFFSEC · Offensive Security

Three security appliances, one three-day deadline: reading the September KEV batch

Cisco Secure FMC, Citrix NetScaler and Fortinet FortiOS entered the CISA catalogue within a day of each other, all under active exploitation. For at least two of the three, patching does not close the incident.

The batch

Three vulnerabilities in security appliances entered the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue in the second week of September 2026, with a remediation deadline of 12 September for federal civilian agencies under Binding Operational Directive 22-01 [1]. Sources differ on the addition date. SecurityWeek, BleepingComputer and The Hacker News record 9 September [2][3][1]; SOCRadar and Security Arsenal record 10 September [4][5]. The deadline is not disputed. Either reading gives agencies two to three days.

The three are CVE-2026-20079 in Cisco Secure Firewall Management Center, an authentication bypass in the web interface rated CVSS 10.0 that yields root-level command execution to an unauthenticated remote attacker [6][7]; CVE-2026-19490 in Citrix NetScaler ADC and NetScaler Gateway, an authentication bypass rated CVSS 9.3 affecting appliances configured as an AAA virtual server or Gateway, covering SSL VPN, ICA Proxy, CVPN and RDP Proxy [8][9]; and CVE-2025-25249 in Fortinet FortiOS and FortiSwitchManager, a heap-based buffer overflow permitting unauthenticated remote code execution [10][11].

The Fortinet score is contested. The Hacker News records 7.3 [1], SecurityWeek 7.4 [10], SOCRadar 9.8 [11]. That range spans a triage boundary in most organisations, so treat the vendor advisory as authoritative and the public score as unreliable.

The Cisco case is the instructive one

Cisco patched CVE-2026-20079 in March 2026 with no evidence of exploitation at the time [6][7]. Log entries consistent with exploitation appear from 23 July 2026 [3]. Cisco's product security team became aware of exploitation in August, and confirmed it publicly on 9 September [3][2]. That is roughly seven weeks between first observable activity and public warning, and about six months between patch availability and the exploitation window.

Talos published three activity clusters on 9 September [12]. UAT-12197, which Talos does not attribute, deployed JSP web shells and Java-based command executors to exfiltrate credentials from internal databases [12]. UAT-11823, which Talos assesses with high confidence overlaps with Sandworm, established Netcat reverse shells, harvested managed-device configurations and deployed Cyclops Blink, an ELF implant with DNS-over-HTTPS resolution, file administration, credential harvesting and network scanning [12]. UAT-11988, which Talos assesses with high confidence is a Qilin affiliate, used static credentials for reconnaissance through legitimate FMC utilities, established SOCKS5 proxies and reverse SSH tunnels, then deployed antivirus killers and ransomware [12].

Those are Talos assessments, reported as such. Cyber Daily notes the Australian Cyber Security Centre issued earlier 2026 warnings on Russian state-sponsored targeting of vulnerable network devices, placing this activity in a regional context APAC defenders already hold advisories for [15].

The second Cisco vulnerability is the detail worth carrying forward. CVE-2026-20316, a static credentials issue rated CVSS 5.3, was disclosed on 29 July 2026 after a report from Jimi Sebree of Horizon3.ai [13][12]. Alone it grants a low-privileged account. It is what the ransomware cluster used for initial access [12][13]. A 5.3 in a business application is deferrable. A 5.3 in the appliance that manages the firewall estate is not.

Affected version ranges are also reported inconsistently. Horizon3 lists FMC branches 6.4 through 10.0 [7]; SOCRadar lists patches for 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 [4]. Check the vendor software checker against the specific deployment rather than any secondary list.

Patching does not close the incident

This is the operative point across all three.

For Fortinet, SOCRadar states that PivotC2 executes as an independent background process that survives termination of its parent, and that patching alone does not eliminate an existing infection: compromised appliances require full restoration from clean backups plus comprehensive credential rotation [11]. PivotC2 is a Node.js remote access tool providing interactive shell, file operations, SOCKS5 and HTTP tunnelling, port forwarding, CIDR scanning and credential harvesting with automated decryption of FortiGate configuration secrets [11][10]. Where it ran, assume the device configuration is in the operator's hands.

For Cisco, SOCRadar notes that patches prevent future exploitation but may not address existing compromise [4]. Cisco's own guidance on the related ASA and FTD campaign is more direct: reset affected devices to factory defaults and replace all credentials, certificates and keys [14]. That document also records a persistence mechanism preserved across upgrade to fixed releases, implemented by modifying ROMMON on legacy ASA 5500-X hardware without Secure Boot, which Cisco assesses is related to the same actor as the ArcaneDoor campaign [14].

For Citrix the issue is session state. An authentication bypass that yields a valid session is not undone by the patch that closes the bypass.

Scale and exposure

Campaign figures differ materially. On Fortinet, The Hacker News reports over 3,000 IP addresses targeted with 178 devices infected [1]; SecurityWeek reports over 30,000 targeted with the same 178 infected, predominantly in the United States, and at least two intrusions resulting in data theft [10]. The infection count agrees; the targeting count differs by an order of magnitude. SOCRadar and SecurityWeek assess the operators as likely Russian-speaking, and note the malware itself may have been developed with AI assistance [10][11].

On Citrix, Ryan Dewhurst of Previdian reported that on 3 September a NetScaler sensor received requests matching the public proof of concept from three source addresses geolocated to Australia, the United States and Germany, and stated that these were exploitation attempts which did not confirm successful compromise of real-world systems [9]. The Hacker News reports honeypot data of 56 attempts since 3 September, 36 of them on 8 September [1]. Shadowserver tracks roughly 22,000 NetScaler ADC appliances and close to 1,700 Gateway instances exposed online, with patch status and vulnerable configuration counts unknown [9]. Rapid7 notes that appliances with SAML authentication actions or configured authentication and VPN virtual servers carry higher risk [8].

What to do

  • Patch to vendor-specified fixed builds, then treat the appliance as suspect rather than resolved. Cisco hotfixes were available immediately; the comprehensive FMC hardening release is reported as the week of 16 September by Talos [12] and the week of 14 September by Cyber Daily [15].
  • Hunt before assuming clean. Cisco published Snort SIDs 66075 to 66080 for CVE-2026-20079, 66883 for CVE-2026-20316, and 66960 to 66961 for the associated malware [12][7]. SOCRadar published filesystem and command-and-control indicators for PivotC2 [11]. BleepingComputer published the sudo log signature associated with FMC exploitation [3].
  • Rotate what the appliance held: configurations, local accounts, certificates, VPN pre-shared keys, and any credential it could decrypt. On FortiGate, assume full configuration exfiltration where PivotC2 is found [11].
  • Terminate active sessions after patching NetScaler and review authentication logs across the exposure window, rather than only from the patch date.
  • Remove management interfaces from the internet. Help Net Security records restricting FMC management interface internet access as the stated alternative where patching is delayed [13].
  • Re-rate medium-severity findings on security appliances. The 5.3 in this batch produced ransomware access [12].

Domain view

Mandiant's M-Trends 2026 places exploitation as the leading initial infection vector at 32%, the sixth consecutive year it has held that position [16]. The devices in this batch are the ones that terminate VPNs, enforce policy and manage the firewall estate. Compromising a management centre is not lateral movement into an environment; it is acquisition of that environment's controls, including the telemetry a defender would use to notice.

Two conclusions follow for practitioners. The first is that severity scoring on appliances should be weighted by what the device governs, not only by exploitability. The second concerns timing. The federal three-day deadline reads as arbitrary until it is set against the seven weeks between first exploitation evidence and public confirmation on the Cisco flaw [3]. Defenders are not being asked to respond to a new vulnerability. They are being asked to close a window that has already been open, and that a state-nexus cluster and a ransomware affiliate are both reported to have used [12].

For APAC organisations running these products at the edge, this week's exercise is inventory rather than analysis: which appliances are internet-facing, when each was last patched, who holds their credentials, and whether logs would show if that last answer had changed.

Sources

Every R3KONX article cites its primary material. 16 sources, in order of first citation. Links open the original publication.

  1. CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline The Hacker News · 2026-09-10
  2. Organizations Warned of Cisco Secure FMC Exploitation SecurityWeek · 2026-09-10
  3. Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks BleepingComputer · 2026-09-09
  4. Cisco FMC CVE-2026-20079 Actively Exploited SOCRadar · 2026-09-10
  5. CISA KEV Alert: CVE-2026-20079 Plus Citrix and Fortinet Flaws Under Active Exploitation Security Arsenal · 2026-09-10
  6. CVE-2026-20079 - Cisco FMC Authentication Bypass RCE Analysis VulnCheck · 2026-03-26
  7. CVE-2026-20079: Cisco FMC Auth Bypass Horizon3.ai · 2026-03-24
  8. CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway Rapid7 · 2026-08-19
  9. Critical Citrix NetScaler auth bypass now leveraged in attacks BleepingComputer · 2026-09-04
  10. Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks SecurityWeek · 2026-09-10
  11. CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT SOCRadar · 2026-09-10
  12. Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos · 2026-09-09
  13. Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) Help Net Security · 2026-09-10
  14. Continued Attacks Against Cisco Firewalls (version 2.3) Cisco Product Security Incident Response Team · 2026-04-24
  15. Patch now! Cisco warns of state and criminal hackers targeting a pair of Secure Firewall Management Center vulnerabilities Cyber Daily · 2026-09-11
  16. M-Trends 2026 Report: Executive Edition Mandiant / Google Cloud · 2026

Researched and written by the R3KONX Analysis Desk from the cited primary material, with AI assistance in research and drafting. Methodological caveat: CVSS scores, catalogue addition dates, affected version ranges and campaign scale figures differ between sources and are reported here as they differ; vendor advisories are authoritative for version and patch decisions. Attribution statements are the assessments of the named researchers, not independent R3KONX findings. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.