CISA added an authentication-bypass flaw in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-19490, and a heap-based buffer overflow across several Fortinet products, tracked as CVE-2025-25249, to its Known Exploited Vulnerabilities catalog on September 9, giving federal civilian agencies until September 12 to patch both. Citrix’s own advisory rates the NetScaler flaw 9.3 on CVSS 4.0 and says an unauthenticated attacker can bypass authentication on an appliance configured as a Gateway or AAA virtual server, reachable through SSL VPN, ICA Proxy, CVPN or RDP Proxy configurations. The Fortinet flaw hits FortiOS, FortiSwitchManager and FortiSASE, letting an attacker execute unauthorized code through specially crafted packets.

Both entries carry a detail CISA does not attach to every KEV addition: a forensic triage requirement under Binding Operational Directive 26-04, on top of the standard patch mandate. That flag applies only when CISA has reason to check for evidence of prior compromise, not just to close the door going forward, and it did not appear on several other vulnerabilities CISA added to the catalog this same week. For NetScaler and Fortinet administrators, a three-day patch window is the visible deadline, but the forensic triage requirement is the part that should reset how urgently a security team treats these two specifically: CISA is telling federal agencies to assume compromise may have already happened and look for it, not simply to assume the patch closes the risk.

Both products sit at the network edge, authenticating remote users before traffic ever reaches an internal application, which is exactly the position that has made VPN gateways and SSL concentrators the preferred entry point for ransomware affiliates and nation-state actors alike over the past two years. Enterprises running either product outside the federal government are not bound by the September 12 deadline, but the forensic triage signal is a reasonable one to borrow regardless of sector.

Source: Citrix

Related: Cisco Firewall Flaw Hits CISA’s List With a Day to Patch and The Patch Window Has Collapsed as NetScaler and ColdFusion Flaws Are Weaponized Within Hours of Disclosure.