CVE Digest

CVE Digest — September 9, 2026

  • Security Bulletin
4 CVE 4 KEV

4 vulnerabilities were added to the CISA KEV catalog on September 9, 2026 and published on NVD. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.

CVEProductCVSSSeveritySummaryReferences
CVE-2026-19490 KEVCitrix NetScalerUnknownCitrix NetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel. When configured as an AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote attacker may bypass authentication.
CVE-2025-25249 KEVFortinet Multiple ProductsUnknownFortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow that allows an attacker to execute unauthorized code or commands via specially crafted packets.
CVE-2026-87491 KEVGoogle Chromium V8UnknownGoogle Chromium V8 contains an out-of-bounds write that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. It may affect multiple Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera.
CVE-2026-20079 KEVCisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementUnknownCisco Secure Firewall Management Center (FMC) Software and Security Cloud Control (SCC) Firewall Management contain an authentication bypass via an alternate path or channel. An unauthenticated remote attacker could bypass authentication, run script files, and gain root access t…

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.