Cyber Threat Intel 5 min read

CISA Has Logged 37 Newly Exploited Flaws in 30 Days

CISA's exploited-vulnerability catalogue has taken 37 new entries in 30 days, including this week's Citrix NetScaler authentication bypass and a 2025 Fortinet flaw.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 11 Sep 2026, 5:45 PM (SGT)
Share:
Bar chart: twelve KEV entries in the last seven days, eleven in the seven before that, eleven across the fortnight before that Bar chart: twelve KEV entries in the last seven days, eleven in the seven before that, eleven across the fortnight before that RECATOOLS graphic
Advertisement

11 SEP 2026 — CISA added three more actively exploited flaws to its Known Exploited Vulnerabilities catalogue this week, in Cisco, Citrix and Fortinet products, with a federal patch deadline of 12 September. That takes the catalogue to 37 new entries in 30 days — twelve in the last seven, eleven the week before, eleven across the fortnight before that.

This week's three

The headline entry is CVE-2026-19490, an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway at CVSS 9.3. NetScaler sits at the edge of corporate networks doing remote access, which is the position that makes an authentication bypass serious rather than merely severe.

Alongside it, CVE-2025-25249, a heap-based buffer overflow affecting Fortinet FortiOS, FortiSwitchManager and FortiSASE at 7.3, and a Cisco flaw completing the set.

The Fortinet identifier is worth a second look: CVE-2025-25249. A 2025 CVE reaching the exploited catalogue in September 2026 is a flaw that sat available for a year before anyone recorded it being used.

37New KEV entries in 30 days
12In the last seven days alone
9.3The Citrix NetScaler authentication bypass
CVE-2025The Fortinet flaw is a year old

Thirty-seven in a month is a rate

Roughly 1.2 newly exploited vulnerabilities per day, sustained across four weeks, is the actual finding, and it lands differently from any single advisory.

An organisation cannot respond to that as a series of emergencies. Twelve entries in a week is more than most security teams can individually assess, let alone patch, and the teams running the affected products are frequently the same small ones each time — edge appliances tend to be owned by whoever also owns the firewall and the VPN.

The honest read for a defender is that KEV has stopped being an alert and become a workload. What it needs is a standing weekly process against an asset inventory, and the organisations most affected are the ones least likely to have either.

Is exploitation rising or is detection

The number cannot answer this, and saying so is better than picking the alarming reading.

A KEV entry requires evidence that a flaw is being exploited. The catalogue therefore grows with exploitation and with the ability to observe it, and those are different things. More vendors publishing telemetry, more researchers reporting, and more attention on edge devices would all push the count up without any change in attacker behaviour.

What can be said is what the entries have in common. The recurring names are edge infrastructure — Citrix, Fortinet, Cisco, and in recent weeks SonicWall, MikroTik and N-able — which is the pattern we have been following in software at the internet-facing edge all month.

Citrix again

NetScaler has been here before. We covered a CitrixBleed-class flaw exploited within a day of disclosure in July, and the product family has produced a series of these.

The reason is structural rather than a comment on Citrix engineering. A remote access gateway is by definition reachable from the internet, holds credentials or session material, and sits in front of the network rather than inside it. Every one of those properties raises the value of a flaw in it.

Advertisement

For anyone running NetScaler, an authentication bypass at 9.3 is the shape that has historically been followed by mass scanning within days. The federal deadline is 12 September; there is no reason for a private operator to move slower than that.

The year-old CVE is the uncomfortable one

CVE-2025-25249 entering the catalogue now means one of two things, and neither is comfortable.

Either the flaw has been exploited quietly for some period and has only now been observed, in which case affected organisations have a detection gap rather than a patching gap. Or exploitation began recently, which would mean attackers are working back through year-old advisories and finding unpatched estates. That strategy only pays if plenty exist.

Both readings point the same way for a defender: the age of a CVE says nothing about whether you are currently exposed to it, and an inventory check against the whole catalogue is worth more than reacting to this week's three.

What to do with 37

Filter by what you actually run, which reduces 37 to a handful for most organisations and is the step that makes the catalogue usable. Prioritise anything internet-facing and anything that grants access rather than information.

Then check whether the products on that list are ones you would find out about. A KEV entry only helps an organisation that knows it operates the product, and in edge infrastructure the appliance nobody remembers installing is the recurring theme of every incident we have written up this month.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement