← Knowledge Center
Advisory CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, CVE-2026-20079

CISA Flags Actively Exploited Citrix and Cisco Authentication Bypass Flaws

CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Two of them are directly identity/access-relevant: CVE-2026-19490, a Citrix NetScaler authentication bypass using an alternate path or channel, and CVE-2026-20079, a Cisco Firewall Management Center authentication bypass of the same class. The other two—CVE-2025-25249 (Fortinet heap-based buffer overflow) and CVE-2026-87491 (Chromium V8 out-of-bounds write)—round out the batch.

Authentication bypass flaws in edge and management devices like NetScaler and Cisco FMC are especially dangerous because they let attackers reach administrative functions without valid credentials. Compromise of these gateways often becomes a springboard for stealing credentials, pivoting into internal networks, and ultimately targeting Active Directory and other identity infrastructure.

What to take away: Under BOD 26-04, FCEB agencies must prioritize rapid remediation of KEV-listed flaws on publicly exposed assets, and all organizations should patch the NetScaler and FMC bypasses immediately while auditing for signs of unauthorized access.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.