York Computer logo York Computer
Managed IT & Security
Cybersecurity News

CISA Flags Actively Exploited Cisco, Citrix, and Fortinet Flaws — Sept 12 Patch Deadline

York Computer

On September 9, the U.S. Cybersecurity and Infrastructure Security Agency issued an emergency-tier warning covering three separate vulnerabilities in Cisco, Citrix, and Fortinet products — all being actively exploited, all sitting on gear that small businesses commonly use for firewalls, remote access, and VPN. Federal agencies were given until September 12 to patch. If your business runs any of this equipment, or your managed IT provider does on your behalf, this is a stop-what-you're-doing moment.

What CISA warned about

CISA on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply the patches by September 12, 2026. The KEV catalog is the government's shortlist of bugs that criminals are already using against real victims — not theoretical risk.

The headline flaw is CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) with a maximum CVSS score of 10.0. The flaw allows an unauthenticated remote attacker to execute scripts and commands with root privileges on affected devices. In plain English: an attacker on the internet can take full control of the console that manages your Cisco firewalls, without ever logging in.

The second flaw, CVE-2026-19490 (CVSS score of 9.3), impacts all NetScaler ADC and NetScaler Gateway appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. The authentication bypass flaw has been exploited in the wild since at least September 3. Citrix NetScaler is the box many mid-sized businesses use for employee remote access — exactly the kind of appliance attackers love to compromise because it sits at the network edge.

The third is a Fortinet flaw added to KEV the same day. All three carry the same September 12 federal deadline.

Why this matters for a small business in York County

You probably don't operate a Cisco FMC or a Citrix NetScaler yourself. But your bank does. Your law firm does. Your accountant, your health system, your suppliers — many of them do. When these edge devices get compromised, the fallout ripples downstream into everyone connected to them.

More directly: if your business has any kind of managed firewall, site-to-site VPN, or remote-access gateway, there's a real chance one of these three vendors is in your stack. One attack cluster combined CVE-2026-20079 with CVE-2026-20316, a separate Secure FMC vulnerability involving static credentials. That activity led to reverse shell and proxy deployment and ultimately a variant of Cyclops Blink malware. Talos associated the activity with clusters it tracks separately, while another FMC intrusion involving CVE-2026-20316 was linked to ransomware-related activity. Translation: the actors exploiting these bugs include nation-state groups and ransomware crews. The end game is your data and your money.

What your managed-IT provider should be doing this week

A competent MSP is already on this. If you use York Computer's managed IT services, or any comparable provider, here is what should be happening right now:

1. **Inventory.** Confirm whether any Cisco Secure FMC, Citrix NetScaler ADC/Gateway, or affected Fortinet appliances are in your environment — including anything a vendor or landlord manages on your behalf.

2. **Patch immediately, not next maintenance window.** Do not wait for a routine maintenance window given active exploitation has been confirmed by both Cisco and CISA. There is no workaround for CVE-2026-20079. The fix is the patch.

3. **Get the management interfaces off the public internet.** Ensuring that the FMC interface cannot be accessed from the internet significantly reduces the risk of exploitation. The same principle applies to every admin console on your network.

4. **Hunt for prior compromise.** Patching stops future exploitation but does not undo damage from an attack that already happened. Cisco advises customers who discover the indicators of compromise to contact its TAC for support, warning that installing the hot fixes will prevent future exploitation but will not remediate devices already compromised.

If you have an internal IT person and want a second set of eyes for emergencies exactly like this one, co-managed IT support is designed for that scenario — your person owns the day-to-day, we provide the after-hours muscle and the vulnerability response.

The question to ask this week

Send your IT provider a short email today: "Are any of the three CVEs in CISA's September 9 KEV update — CVE-2026-20079 (Cisco FMC), CVE-2026-19490 (Citrix NetScaler), or the Fortinet flaw — present in our environment, and if so, are they patched?" You should get a straight answer within a business day. If you don't, that itself is the answer.

What York Businesses Should Do

York County businesses using outside vendors for firewall management, remote access, or point-of-sale connectivity should confirm this week that their provider has already patched. If nobody can give you a clear yes-or-no on these three CVEs by Friday, York Computer can run an independent check.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles