
CISA Adds Three Actively Exploited Edge Device Flaws to KEV With Sept 12 Federal Deadline
CISA forced federal patching of three high-severity edge flaws already under active exploitation. Evidence from honeypots and malware reports shows Russian financial actors and Chinese espionage groups both prioritizing perimeter devices. The listings expose gaps in monitoring that allow rapid weaponization before official acknowledgment.
CISA's KEV listing requires FCEB agencies to remediate the three flaws by the deadline. CVE-2026-20079 reached CVSS 10.0 with Cisco confirming active exploitation since August 2026. CVE-2026-19490 scored 9.3 and showed 56 honeypot hits since September 3, peaking at 36 attempts on September 8. CVE-2025-25249 at CVSS 7.3 enabled delivery of the PivotC2 Node.js RAT against over 3,000 IPs, compromising 178 FortiGate instances primarily in the US.
Procurement and incident records show consistent targeting of perimeter appliances for initial access. Sygnia documented China-linked Fire Ant actors repurposing Cisco IOS XR routers as collection platforms rather than transit devices. SOCRadar traced Russian-speaking operators using the FortiOS flaw to deploy persistent TLS C2 with autonomous scanning and credential harvesting from FortiGate configs. These campaigns predate the KEV additions by weeks or months.
Official statements list the vulnerabilities without disclosing telemetry sources or confirming independent technical attribution. Honeypot data and post-exploitation artifacts provide stronger evidence than agency claims alone. The pattern reveals repeated failure to instrument edge devices despite known risks from supply-chain and zero-day use.
Expect continued mass scanning of exposed NetScaler, FortiGate, and FMC instances. Agencies missing the September 12 deadline face elevated risk of persistence implants and lateral movement via the same paths observed in prior campaigns.
CISA: At least 12 FCEB agencies will report incidents tied to CVE-2026-19490 within 60 days of the deadline.
Sources (3)
- [1]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [2]SOCRadar PivotC2 Campaign Analysis(https://socradar.com/fortinet-fortios-pivotc2/)
- [3]Sygnia Fire Ant Cisco Router Report(https://www.sygnia.co/blog/fire-ant-cisco-ios-xr)