Article
CISA Adds Four Exploited Flaws to the KEV Catalog
CISA added four already-exploited bugs on 9 September 2026: Fortinet, NetScaler, Chromium V8, and Cisco FMC. Who should care, and what to do this week.
On 9 September 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog because it had evidence they were already being used in attacks. The primary source is CISA’s alert, CISA Adds Four Known Exploited Vulnerabilities to Catalog.
- CVE-2025-25249, a heap-based buffer overflow in multiple Fortinet products.
- CVE-2026-19490, an authentication bypass on Citrix NetScaler that uses an alternate path or channel.
- CVE-2026-87491, an out-of-bounds write in Google Chromium’s V8 JavaScript engine.
- CVE-2026-20079, an authentication bypass on Cisco Secure Firewall Management Center that uses an alternate path or channel.
A KEV listing is not a CVSS score. It is a statement that exploitation has been observed, so these four move ahead of bugs that are still only theoretical. This is a different four from the SharePoint and RouterOS pair EngPlain covered later in September. Treat each KEV week as its own patch queue.
Who should care
Anyone who terminates remote access or manages firewalls through Fortinet, Citrix NetScaler, or Cisco FMC. Anyone whose staff browsers still run a Chromium build older than the vendor fix for CVE-2026-87491. Federal Civilian Executive Branch agencies are bound by Binding Operational Directive 26-04. Everyone else still has internet-facing appliances and browsers that visit untrusted pages.
If you do not run those products, this alert is not your ticket. If even one of them is reachable from a network you do not fully control, it is.
What the four entries are
The four catalog rows are Fortinet (CVE-2025-25249), Citrix NetScaler (CVE-2026-19490), Chromium V8 (CVE-2026-87491), and Cisco Firewall Management Center (CVE-2026-20079). Use the vendor advisory named in each KEV row. Confirm the build you landed on, not only that the installer finished.
Keep this in the same habit as the SharePoint and RouterOS briefing: one alert, one ticket, one due date. Do not merge the two CISA weeks into a single change window. If you only run browsers, the Chromium row is still yours. If you only run appliances, skip the browser fleet and still write the due date.
What BOD 26-04 changes
Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, is the vulnerability-management rule for Federal Civilian Executive Branch agencies. It keeps the KEV catalog at the center of that process. Agencies must patch high-risk KEV entries on publicly exposed assets, and they must check whether an incident was already in progress before the patch landed.
In September 2026 a large share of new KEV rows carried a three-day due date rather than fourteen. That clock is for FCEB. A company without a directive still needs a date on the ticket, or these four sit in a backlog with no owner. Write the due date the same day you file the change.
What to do
- Inventory Fortinet appliances, Citrix NetScaler, Cisco FMC, and Chromium-based browsers, including the boxes that never made it into the CMDB.
- Apply the vendor updates for these four CVEs. Record the build you landed on, not only that the ticket closed.
- If any of those products were reachable from the internet before the patch, review sessions, new admins, and config changes in the days around 9 September 2026.
- On browsers, ship the Chromium, Chrome, or Edge update and retire versions that cannot take it.
- Federal teams follow BOD 26-04. Everyone else still needs a name and a day on the same four CVEs.
If you think a KEV entry is missing
CISA still takes nominations through the KEV form. A nomination needs a CVE ID, evidence of in-the-wild use, and clear mitigation. Track the catalog at cisa.gov/known-exploited-vulnerabilities-catalog. This note is a reading of the 9 September 2026 alert. Patch steps come from the vendor pages named in that catalog, not from a summary.