Critical Authentication Bypass (CVE‑2026‑20079) in Cisco FMC Added to CISA KEV Catalog Alongside Fortinet, Google Chromium V8, and Citrix NetScaler Flaws
What It Is – CISA has placed four actively‑exploited flaws into its Known Exploited Vulnerabilities (KEV) catalog, the most severe being CVE‑2026‑20079 in Cisco Secure Firewall Management Center (FMC). The Cisco flaw is an authentication‑bypass on the web UI that lets unauthenticated attackers execute arbitrary scripts and obtain root on the underlying OS.
Exploitability – All four vulnerabilities are confirmed in the wild; the Cisco issue carries a CVSS 10.0 score, the Google V8 bug (CVSS 8.8) is a zero‑day actively exploited in the wild, Fortinet’s heap‑overflow (CVSS 8.1) and Citrix’s SAML redirect bypass (CVSS 9.3) are also being leveraged by threat actors.
Affected Products –
- Cisco Secure FMC (web interface)
- Fortinet FortiOS / FortiSwitchManager (cw_acd daemon)
- Google Chrome V8 engine (Chrome 153.0.8010.36+)
- Citrix NetScaler ADC & Gateway (SAML HTTP‑Redirect binding)
Why It Matters for Trust & Control Assurance
- Vulnerability Management – Demonstrates the need for continuous, automated tracking of vendor‑issued CVEs and rapid patch deployment to satisfy the control objective of “identify, assess, and remediate vulnerabilities.”
- Audit Evidence – Maintaining verifiable remediation records (patch version, deployment date, validation test) provides defensible evidence for audits across SOC 2, ISO 27001, NIST CSF, etc.
- Supply‑Chain Assurance – Third‑party products are a common attack surface; showing timely oversight of these components signals strong vendor risk governance to enterprise buyers.
Recommended Actions
- Run an immediate inventory of all Cisco FMC, Fortinet, Chrome, and Citrix NetScaler instances in your environment.
- Apply the vendor‑released patches (Cisco FMC v7.14.2+, Chrome 153.0.8010.36+, FortiOS 7.4.5+, Citrix NetScaler 13.1‑HF5) and verify successful installation.
- Update your vulnerability‑management workflow to ingest CISA KEV feeds automatically and map each CVE to the relevant control objective.
- Capture remediation evidence (patch version, scan results) in a centralized control‑mapping repository for audit readiness.
Source: Security Affairs