Security · 2 MIN READ

CISA KEV Additions Put Cisco and Fortinet Patching First

CISA added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities catalog. The additions give network teams a clear reason to identify affected Cisco and Fortinet devices, prioritize patching, and verify remediation against current asset and firmware records.

CISA KEV Additions Put Cisco and Fortinet Patching First

CISA added three vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities catalog. The agency set a September 12, 2026 patch deadline for Federal Civilian Executive Branch agencies, underscoring the urgency created by confirmed exploitation. Network teams can use the additions to prioritize affected infrastructure rather than treating every vulnerability as equally urgent.


What CISA Added

The three flaws each affect products from Cisco, Citrix, or Fortinet. The source identifies CVE-2026-20079 among the additions and reports a CVSS score of 10.0.

Inclusion in the KEV catalog indicates that exploitation is occurring in the wild. For infrastructure teams, that makes accurate device, firmware, and remediation data essential to determining where action is required.


Turn the KEV Alert Into an Asset-Level Plan

A practical response begins by translating the advisory into a list of specific devices and owners. Network teams should:

  • Identify deployed Cisco and Fortinet devices that may fall within the affected product scope.

  • Confirm each device model and current firmware or software release.

  • Review the applicable vendor guidance and approved remediation.

  • Back up configurations before maintenance begins.

  • Apply the required updates according to operational priority.

  • Refresh asset data after maintenance and confirm that affected versions are no longer present.

  • Record exceptions, unavailable devices, and deferred work for follow-up.

This process helps prevent exposed devices from being missed because of incomplete inventories, stale spreadsheets, or unclear ownership.


Verification Matters After Patching

Installing an update is only part of remediation. Teams also need to confirm that the intended devices were reached, that their recorded firmware changed as expected, and that vulnerability findings no longer remain associated with those assets.

Configuration history also provides a useful safety net around urgent maintenance. A verified pre-change snapshot makes it easier to investigate unexpected behavior and restore a known configuration if necessary.


How ConnectMyAssets Helps

ConnectMyAssets provides an on-prem workflow for managing the Cisco and Fortinet network devices involved in this type of response:

  • Dynamic CMDB automatically discovers supported devices and maintains asset, firmware, and topology context.

  • CVE Tracking shows vulnerabilities at the individual asset level, helping teams focus on devices connected to urgent KEV entries.

  • Backup & History creates SHA256-verified configuration versions and supports one-click configuration rollback around maintenance work.

  • Compliance Engine supports CISA-aligned assessment and weighted scoring, making unresolved findings easier to track.

  • Automation & ZTP supports repeatable changes across supported network infrastructure when remediation must be coordinated at scale.

After patching, teams can refresh discovery data and review firmware and CVE status to verify that remediation is reflected in the managed inventory. ConnectMyAssets runs as a hardened OVA with no cloud dependency, so device data, credentials, configurations, and vulnerability records remain on-prem.

Source: The Hacker News

Share this articleLinkedIn ↗Email ↗

Keep exploring.

All articles
Security

Critical Check Point Management Flaw Allows Root Code Execution

A critical vulnerability in Check Point Security Management and Log Servers could let an unauthenticated network attacker execute code as root. Because the management server controls firewall policy and administrator access, organizations should apply the LivePatch fix and verify every potentially exposed system.

Read article
Security

Check Point Management-Server RCE: What to Track

CERT-FR has reported a vulnerability in Check Point products that can allow remote arbitrary code execution. Administrators should identify affected management assets, apply the required vendor updates, and search SmartConsole logs for the login-failure pattern highlighted in the advisory.

Read article
Security

Cisco ISE Zero-Day Under Active Attack

Cisco has disclosed a maximum-severity authentication-bypass vulnerability in ISE that is already being exploited. Network teams should identify affected systems, follow Cisco’s remediation guidance, and document patch or mitigation status across their network-access infrastructure.

Read article