U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

2026-09-10T20:51:38Z1fad732b9f0f1c5cd1ad30de3bce80e7f91e7a190a20bb0290d9f211521e8145
CVE-2026-20079CVE-2026-75650CVE-2026-87491AI securityAdobe CommerceCISA KEVChromeChromium V8Cisco SecureCitrix NetScalerF5 BIG-IP APMFortinetLinux rootkitMicrosoft DefenderMicrosoft WindowsN-able N-centralactively exploited vulnerabilitiesexploit kitfileless malwaremodel extractionnation-state activitypatch managementweb shellzero-day

What happened

SecurityAffairs reports multiple high-impact September 2026 security developments, including CISA additions of actively exploited Cisco, Chromium V8, Fortinet, Citrix NetScaler, Windows, N-able N-central, and Adobe vulnerabilities to the KEV catalog; an actively exploited Chrome V8 zero-day; nation-state use of a Chrome/Windows exploit kit; a fileless Linux rootkit targeting F5 BIG-IP APM; a Microsoft Defender zero-day proof of concept; and Microsoft’s record September Patch Tuesday. The feed also covers AI model extraction campaigns and unsafe AI-agent behavior.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1fad732b9f0f1c5cd1ad30de3bce80e7f91e7a190a20bb0290d9f211521e8145
Enrichment time
2026-09-10T20:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog · Baitaphish