The U.S This article explores vulnerability citrix netscaler. . Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-20079 (CVSS score: 10.0) - The Cisco Secure Firewall Management Center (FMC) Software contains a vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device. An attacker could exploit this vulnerability to obtain root access to the underlying operating system. CVE-2026-19490 (CVSS score: 9.3) - An authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway when configured as a AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN or RDP Proxy).

CVE-2025-25249 (CVSS Score: 7.3) - Fortinet FortiOS, FortiSwitchManager, and FortiSASE has a heap-based buffer overflow vulnerability that allows a remote unauthenticated attacker to execute arbitrary code or commands via a specially crafted request. Once the actor controlled the router, it provided a vantage point to monitor traffic traversing secure network paths. We have observed an increase in exploitation activity against Previdian’s honeypot systems for CVE-2026-19490.

An auto-mode flag is provided to allow autonomous operation, where a predefined command sequence is automatically executed after the initial infection.The data once again shows how often malicious actors use unsecured perimeter edge devices as an initial access point. SOCRadar recommends that organizations using Fortinet products restrict internet access, investigate indicators of compromise, rotate credentials and apply the latest patches.