CISA Adds Four Known Exploited Vulnerabilities to Catalog
Overview
The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that these flaws are currently being exploited in the wild. The vulnerabilities include a heap-based buffer overflow in Fortinet products (CVE-2025-25249), an authentication bypass in Citrix NetScaler (CVE-2026-19490), an out-of-bounds write in Google Chromium's V8 engine (CVE-2026-87491), and another authentication bypass affecting Cisco Firewall Management Center (CVE-2026-20079). These vulnerabilities pose significant risks, especially to federal agencies, which are urged to prioritize quick remediation efforts based on a directive from CISA. While the directive primarily affects federal entities, CISA encourages all organizations to adopt similar risk-based practices to address these vulnerabilities effectively. Organizations are also invited to report any exploited vulnerabilities not yet listed in the KEV Catalog for evaluation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Fortinet products, Citrix NetScaler, Google Chromium V8, Cisco Firewall Management Center
- Action Required: Federal agencies are required to prioritize rapid remediation of the vulnerabilities listed in the KEV Catalog on publicly exposed assets.
- Timeline: Newly disclosed
Original Article Summary
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Impact
Fortinet products, Citrix NetScaler, Google Chromium V8, Cisco Firewall Management Center
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Federal agencies are required to prioritize rapid remediation of the vulnerabilities listed in the KEV Catalog on publicly exposed assets. Specific patches or updates are not mentioned, but organizations should apply relevant security updates from vendors for the affected products as they become available.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Google, Cisco, and 3 more.