Three new firewall and VPN vulnerabilities landed on CISA’s known exploited list this week. They cover Cisco, Citrix and Fortinet gear. If any of that kit sits on your network, don’t ask whether to act. Ask how fast you can check your version numbers and get a fix installed. None of this needs a security background, though it does take a bit of time and the right questions.
Here’s a plain checklist for IT managers and business owners who don’t have a security team watching every advisory.
Table of Contents
Step 1: Find which firewall and VPN vulnerabilities affect you
The three flaws hit specific products. They are Cisco Secure Firewall Management Center, Citrix NetScaler ADC and Gateway, and Fortinet’s FortiOS, FortiSwitchManager and FortiSASE. Did a third party build or maintain your firewall, VPN or remote access setup? Ask them directly which of these products you use, and which version.
Don’t assume your managed service provider has already fixed it. Ask for written confirmation. Get the exact patched build number they applied. Manage the devices yourself? The version number usually sits on the admin dashboard’s system or about page. Each vendor’s advisory lists exactly which builds are affected.
A quick note on the scores below. CVSS runs from 0 to 10. Anything above 9 usually means an attacker needs no special access and no help from inside your business. All three bugs here clear that bar.
Step 2: Understand what each bug actually does
The Cisco flaw is CVE-2026-20079, CVSS 10.0. It lets an attacker with no credentials reach root access on the Firewall Management Center. They just send crafted requests to its web interface. There’s no workaround, only a hotfix. Cisco has confirmed active attacks since August 2026.
The Citrix flaw is CVE-2026-19490, CVSS 9.3. It affects NetScaler ADC and Gateway when set up for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or as an AAA virtual server. Citrix patched it in August. Honeypot researchers still logged 56 attack attempts since 3 September. Unpatched systems are still being probed hard.
The Fortinet flaw is CVE-2025-25249, CVSS 7.3. It’s a buffer overflow that lets an unauthenticated attacker run code on FortiOS and FortiSwitchManager devices. Attackers are already using it to install a remote access trojan called PivotC2. Researchers count roughly 178 infected devices so far, echoing past Fortinet VPN exposure incidents.

Step 3: Patch in the right order
These three firewall and VPN vulnerabilities don’t all deserve equal urgency, so focus on exposure first, not just the CVSS score. A management console or VPN gateway reachable from the public internet needs attention before an internal-only device. That’s still true whatever the vendor’s severity rating says. Can you only patch one system today? Patch the one an outsider can actually reach.
Check each vendor’s advisory for the exact fixed version, since release trains differ. Fortinet, for instance, fixed the bug across several FortiOS branches on their own: 7.0, 7.2, 7.4 and 7.6. Install the wrong branch’s update and the device stays just as exposed.
Step 4: Confirm you weren’t already compromised
These bugs were being exploited before some businesses even patched them. Check logs against the windows each vendor has confirmed: August 2026 onward for Cisco, early September for Citrix, and July 2026 onward for Fortinet. Then look for unexpected admin sessions, unfamiliar outbound connections from the device itself, or configuration changes nobody on your team made.
Found anything suspicious? Treat the device as compromised, not just patched. A patch closes the door an attacker used to get in. It doesn’t remove anyone who already walked through it.
Step 5: Ask your vendor or MSP the right questions
When you contact whoever manages the device, ask three things. Which fixed version did they apply? When did they apply it? Did they check logs for the attack windows above? A vague “we’re on it” isn’t an answer. No version number, no date? Keep escalating until someone gives you both.
Step 6: Build this into a routine, not a one-off
Firewall and VPN vulnerabilities like these will keep appearing. That’s because these devices are valuable, internet-facing targets, and they always will be. A periodic vulnerability scan catches the gaps a busy IT team misses between patch cycles. So does an occasional independent firewall configuration review, especially on kit that was set up once and never revisited.
None of this needs to be expensive or complicated. Book a single annual review of your external attack surface: firewalls, VPN gateways, anything facing the internet. That one step catches most of what turns a headline like this one into a real incident for your business, since the next firewall and VPN vulnerabilities will land eventually. Put a date in the diary now. Don’t wait for the next vendor advisory to remind you.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.