CISA KEV Additions Put Cisco and Fortinet Patching First
CISA added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities catalog. The additions give network teams a clear reason to identify affected Cisco and Fortinet devices, prioritize patching, and verify remediation against current asset and firmware records.

CISA added three vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities catalog. The agency set a September 12, 2026 patch deadline for Federal Civilian Executive Branch agencies, underscoring the urgency created by confirmed exploitation. Network teams can use the additions to prioritize affected infrastructure rather than treating every vulnerability as equally urgent.
What CISA Added
The three flaws each affect products from Cisco, Citrix, or Fortinet. The source identifies CVE-2026-20079 among the additions and reports a CVSS score of 10.0.
Inclusion in the KEV catalog indicates that exploitation is occurring in the wild. For infrastructure teams, that makes accurate device, firmware, and remediation data essential to determining where action is required.
Turn the KEV Alert Into an Asset-Level Plan
A practical response begins by translating the advisory into a list of specific devices and owners. Network teams should:
- Identify deployed Cisco and Fortinet devices that may fall within the affected product scope.
- Confirm each device model and current firmware or software release.
- Review the applicable vendor guidance and approved remediation.
- Back up configurations before maintenance begins.
- Apply the required updates according to operational priority.
- Refresh asset data after maintenance and confirm that affected versions are no longer present.
- Record exceptions, unavailable devices, and deferred work for follow-up.
This process helps prevent exposed devices from being missed because of incomplete inventories, stale spreadsheets, or unclear ownership.
Verification Matters After Patching
Installing an update is only part of remediation. Teams also need to confirm that the intended devices were reached, that their recorded firmware changed as expected, and that vulnerability findings no longer remain associated with those assets.
Configuration history also provides a useful safety net around urgent maintenance. A verified pre-change snapshot makes it easier to investigate unexpected behavior and restore a known configuration if necessary.
How ConnectMyAssets Helps
ConnectMyAssets provides an on-prem workflow for managing the Cisco and Fortinet network devices involved in this type of response:
- Dynamic CMDB automatically discovers supported devices and maintains asset, firmware, and topology context.
- CVE Tracking shows vulnerabilities at the individual asset level, helping teams focus on devices connected to urgent KEV entries.
- Backup & History creates SHA256-verified configuration versions and supports one-click configuration rollback around maintenance work.
- Compliance Engine supports CISA-aligned assessment and weighted scoring, making unresolved findings easier to track.
- Automation & ZTP supports repeatable changes across supported network infrastructure when remediation must be coordinated at scale.
After patching, teams can refresh discovery data and review firmware and CVE status to verify that remediation is reflected in the managed inventory. ConnectMyAssets runs as a hardened OVA with no cloud dependency, so device data, credentials, configurations, and vulnerability records remain on-prem.
Source: The Hacker News



