← Back to Feed
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CVE-2025-25249CVE-2026-19490CVE-2026-87491CVE-2026-20079
September 9, 2026 · CISA (US-CERT) · Severity: HIGH
The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, and CVE-2026-76461. These flaws affect a range of products and have been confirmed as actively exploited in the wild by threat actors. Federal agencies are required to remediate these vulnerabilities by the specified due dates, and CISA strongly recommends that all organizations prioritize patching these CVEs to reduce their attack surface. The additions reflect the ongoing trend of adversaries quickly weaponizing newly disclosed vulnerabilities.
Key Takeaways
- CISA has added four vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-25249 (Fortinet), CVE-2026-19490 (Citrix), CVE-2026-87491 (Chromium), and CVE-2026-20079 (Cisco FMC).
- The Fortinet heap-based buffer overflow (CVE-2025-25249) and Citrix authentication bypass (CVE-2026-19490) represent critical risks to enterprise network infrastructure.
- Google Chromium's V8 out-of-bounds write (CVE-2026-87491) affects browser security, while Cisco FMC authentication bypass (CVE-2026-20079) targets firewall management systems.
- Federal agencies must apply patches per CISA's Binding Operational Directive, and private sector organizations are strongly advised to prioritize remediation.