11 SEP 2026 — CISA added three more actively exploited flaws to its Known Exploited Vulnerabilities catalogue this week, in Cisco, Citrix and Fortinet products, with a federal patch deadline of 12 September. That takes the catalogue to 37 new entries in 30 days — twelve in the last seven, eleven the week before, eleven across the fortnight before that.
This week's three
The headline entry is CVE-2026-19490, an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway at CVSS 9.3. NetScaler sits at the edge of corporate networks doing remote access, which is the position that makes an authentication bypass serious rather than merely severe.
Alongside it, CVE-2025-25249, a heap-based buffer overflow affecting Fortinet FortiOS, FortiSwitchManager and FortiSASE at 7.3, and a Cisco flaw completing the set.
The Fortinet identifier is worth a second look: CVE-2025-25249. A 2025 CVE reaching the exploited catalogue in September 2026 is a flaw that sat available for a year before anyone recorded it being used.
Thirty-seven in a month is a rate
Roughly 1.2 newly exploited vulnerabilities per day, sustained across four weeks, is the actual finding, and it lands differently from any single advisory.
An organisation cannot respond to that as a series of emergencies. Twelve entries in a week is more than most security teams can individually assess, let alone patch, and the teams running the affected products are frequently the same small ones each time — edge appliances tend to be owned by whoever also owns the firewall and the VPN.
The honest read for a defender is that KEV has stopped being an alert and become a workload. What it needs is a standing weekly process against an asset inventory, and the organisations most affected are the ones least likely to have either.
Is exploitation rising or is detection
The number cannot answer this, and saying so is better than picking the alarming reading.
A KEV entry requires evidence that a flaw is being exploited. The catalogue therefore grows with exploitation and with the ability to observe it, and those are different things. More vendors publishing telemetry, more researchers reporting, and more attention on edge devices would all push the count up without any change in attacker behaviour.
What can be said is what the entries have in common. The recurring names are edge infrastructure — Citrix, Fortinet, Cisco, and in recent weeks SonicWall, MikroTik and N-able — which is the pattern we have been following in software at the internet-facing edge all month.
Citrix again
NetScaler has been here before. We covered a CitrixBleed-class flaw exploited within a day of disclosure in July, and the product family has produced a series of these.
The reason is structural rather than a comment on Citrix engineering. A remote access gateway is by definition reachable from the internet, holds credentials or session material, and sits in front of the network rather than inside it. Every one of those properties raises the value of a flaw in it.
For anyone running NetScaler, an authentication bypass at 9.3 is the shape that has historically been followed by mass scanning within days. The federal deadline is 12 September; there is no reason for a private operator to move slower than that.
The year-old CVE is the uncomfortable one
CVE-2025-25249 entering the catalogue now means one of two things, and neither is comfortable.
Either the flaw has been exploited quietly for some period and has only now been observed, in which case affected organisations have a detection gap rather than a patching gap. Or exploitation began recently, which would mean attackers are working back through year-old advisories and finding unpatched estates. That strategy only pays if plenty exist.
Both readings point the same way for a defender: the age of a CVE says nothing about whether you are currently exposed to it, and an inventory check against the whole catalogue is worth more than reacting to this week's three.
What to do with 37
Filter by what you actually run, which reduces 37 to a handful for most organisations and is the step that makes the catalogue usable. Prioritise anything internet-facing and anything that grants access rather than information.
Then check whether the products on that list are ones you would find out about. A KEV entry only helps an organisation that knows it operates the product, and in edge infrastructure the appliance nobody remembers installing is the recurring theme of every incident we have written up this month.