CISA added a newly disclosed zero-day vulnerability in Cisco Secure Firewall Management Center to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

Reader brief
Through the Reader lens: CISA has added multiple actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a zero-day in Cisco Secure Firewall Management Center. Cisco confirmed that threat actors are leveraging these flaws to steal credentials and deploy ransomware, posing an immediate risk to organizations using the affected management platforms. The KEV update also includes vulnerabilities in Citrix NetScaler and Fortinet products, setting a patch deadline of September 12, 2026, for federal agencies. Because these vulnerabilities target critical network management and edge infrastructure, successful exploitation can lead to severe network compromise and data encryption. Security teams must prioritize applying vendor-provided hotfixes and restricting public internet access to management interfaces to mitigate the immediate threat.
What to watch next
- ,
What was said2
Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.
Tyler Reguly
1 quote“We're continually seeing large numbers of vulnerabilities and we're all starting to feel a little burnt out.”
In the article
…been flagged as actively exploited. "It's hard not to sound like a broken record these days when talking about security updates," Tyler Reguly, Fortra's Associate Director of Security Research and Development, said. " We're continually seeing large numbers of vulnerabilities and we're all starting to feel a little burnt out. I've said it before and I say it again, there is a light at the end of this tunnel and the record numbers of patches for record numbers of vulnerabilities will not last. I'm confident of this. Do everything you can to…
Cisco
1 quote“Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316”
In the article
…the victim's environment, drop tunneling tools to maintain network access, collect credentials, build a target list of endpoints to encrypt, terminate security tools, and deploy Qilin ransomware on selected systems. " Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316 ," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week. The development comes as the U.S. Cybersecurity and Infrastructure Security Agency…
So what3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Cisco Secure Firewall Management Center users credential theft and ransomware· immediate
- Federal agencies patch required· days
- Citrix and Fortinet users patch required· days
Sources4
- [1]The Hacker NewsneutralThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
- [2]The Hacker NewsneutralCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
- [3]The Hacker NewsneutralCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
- [4]The Hacker NewsneutralCisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data