Cisco Firewall Management Center Root Access (CVE-2026-20079)
Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity CVSS 10.0 authentication bypass in Secure Firewall Management Center and Security Cloud Control Firewall Management. An unauthenticated attacker sends crafted HTTP requests to the web interface, abuses an improperly configured boot-time system process, and executes commands as root. No credentials, no interaction, root on the box.
The uncomfortable part is what FMC is: the central management plane for your Cisco firewall estate. One compromised FMC can push policy to every firewall it manages. Cisco says PSIRT became aware of exploitation in August, but the example IOC in the advisory carries a July 23 timestamp and overlaps with the exploited CVE-2026-20316 static credential flaw disclosed in July, so assume attackers may have been inside for weeks. There are no workarounds. Upgrade on-prem FMC now; Cisco has already patched the cloud-hosted SCC service.
For detection, grep /var/log/messages for license.tmp. A sudo invocation of package_info.pl against /var/tmp/license.tmp by the www user means assume compromise and start triage.
Citrix NetScaler Authentication Bypass (CVE-2026-19490)
The same KEV batch adds CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and NetScaler Gateway. Where the appliance fronts an AAA virtual server or a Gateway configuration (SSL VPN, ICA Proxy, CVPN, RDP Proxy), an unauthenticated remote attacker can skip authentication entirely. Citrix shipped fixes on August 21; nineteen days later CISA has confirmed in-the-wild exploitation. Three-day federal clock, forensic triage required.
Fortinet FortiOS Heap Overflow (CVE-2025-25249)
Fortinet rounds out the batch with CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon affecting FortiOS, FortiSwitchManager and FortiSASE. CVSS 7.4, code execution from crafted packets, and despite the sub-9.0 score CISA still put it on the same 72-hour clock with mandatory forensics.
Action
Three perimeter products, three vendors, one 72-hour window that closes September 12. Sequence by blast radius: FMC and SCC first (management plane, no workaround, root), NetScaler AAA and Gateway second (remote access authentication), Fortinet third. Inventory internet-exposed management interfaces today. If your FMC shows the license.tmp indicator, treat the whole managed estate as suspect: rotate credentials, review pushed policies and objects, image the box and triage before you trust that management plane again. Patch Tuesday handed you 974 CVEs this week. CISA just told you which ones come first.

