$ techbeacon▋
CVE & Exploits

CISA Adds Three Critical Flaws to KEV List, Sets Federal Patch Deadline for Mid‑September

CISA Adds Three Critical Flaws to KEV List, Sets Federal Patch Deadline for Mid‑September

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced Wednesday that three newly identified software vulnerabilities affecting Cisco, Citrix and Fortinet have been added to its Known Exploited Vulnerabilities (KEV) catalog.

Under the agency's directive, all Federal Civilian Executive Branch (FCEB) components must install the corresponding security updates by September 12, a deadline that aligns with the agency's regular patch‑window schedule.

The three flaws, each classified as actively exploited in the wild, involve remote code execution paths that could allow attackers to gain unauthorized access to network devices or application servers. While CISA has not disclosed the technical details publicly, the vendors have already released patches that address the weaknesses.

CISA’s KEV list is a curated inventory of vulnerabilities that have been observed in active attacks against U.S. government networks. Adding a flaw to the list triggers mandatory remediation actions for federal agencies, and often serves as a signal for the broader private‑sector community to prioritize mitigation.

Industry analysts note that the inclusion of products from three major vendors underscores the persistent threat landscape targeting critical infrastructure. Both Cisco and Fortinet supply networking and security appliances widely deployed across government and enterprise environments, while Citrix provides virtualization and remote‑access solutions that are similarly high‑value targets.

Federal IT teams are now racing to verify that the patches have been applied across their inventories, a process that can be complicated by legacy systems and the need to test updates before deployment. Agencies that fail to meet the September 12 deadline could face heightened scrutiny and potential penalties under federal cybersecurity compliance frameworks.

Looking ahead, CISA has indicated that it will continue to monitor exploitation activity and may update the KEV catalog as new evidence emerges. The agency also encourages organizations outside the federal sphere to review the KEV entries and apply the patches promptly, citing the broader risk of spillover attacks that leverage the same vulnerabilities.

Stakeholders are advised to consult vendor advisories for detailed remediation steps and to maintain regular vulnerability scanning to ensure that any additional, unlisted weaknesses are identified and addressed before they can be weaponized.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related