CISA Adds Four Exploited Vulnerabilities to KEV Catalog, Including Fortinet, Citrix, Chrome, and Cisco Flaws
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and mandating prioritized patching for federal agencies.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of four new vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). This designation signifies that the vulnerabilities have been observed under active exploitation in the wild, posing a significant and immediate threat to organizations.
The newly added vulnerabilities include CVE-2025-25249, a heap-based buffer overflow affecting multiple Fortinet products; CVE-2026-19490, an authentication bypass vulnerability in Citrix NetScaler; CVE-2026-87491, an out-of-bounds write in Google Chromium's V8 engine; and CVE-2026-20079, an authentication bypass vulnerability in Cisco Firewall Management Center.
These vulnerabilities represent a diverse range of attack vectors, from memory corruption flaws in widely used browser components to authentication bypasses in critical network infrastructure. The inclusion in the KEV catalog means that threat actors are actively leveraging these weaknesses to compromise systems, potentially leading to unauthorized access, data breaches, and disruption of services.
Federal Civilian Executive Branch (FCEB) agencies are particularly impacted by this announcement, as Binding Operational Directive (BOD) 26-04 mandates the prioritization of remediation for vulnerabilities listed in the KEV Catalog, especially those on public-facing assets that grant complete control post-exploitation. While this directive specifically targets federal agencies, CISA strongly encourages all organizations to adopt a risk-based vulnerability management approach and prioritize the patching of these high-risk flaws.
The KEV Catalog serves as a critical resource for organizations to understand which vulnerabilities pose the most immediate threat. By focusing remediation efforts on these actively exploited flaws, organizations can significantly reduce their attack surface and mitigate the risk of compromise.
CISA continuously monitors the threat landscape for evidence of active exploitation and will add new vulnerabilities to the KEV Catalog as they are identified. The agency also provides a nomination form for the public to submit vulnerabilities that they believe warrant inclusion, provided they have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Organizations are urged to review the details of each newly added vulnerability and implement necessary patches or mitigations as soon as possible. Proactive vulnerability management and timely patching remain cornerstone practices for maintaining a strong cybersecurity posture against evolving threats.