← All Cyber Watch editions

Small Business Cyber Watch · September 10, 2026

Small Business Cyber Watch — September 10, 2026

Practical context and recommended next steps for business leaders.

September 10, 2026 — Small Business Cyber Watch

Today’s priority: Review the newest entries in CISA’s authoritative catalog of vulnerabilities known to be exploited in the wild. The most recent catalog additions shown below are dated September 9, 2026.

Citrix NetScaler: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2026-19490 · Added by CISA September 9, 2026

What changed: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 12, 2026.

Fortinet Multiple Products: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVE-2025-25249 · Added by CISA September 9, 2026

What changed: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 12, 2026.

Google Chromium V8: Google Chromium V8 Out of Bounds Write Vulnerability

CVE-2026-87491 · Added by CISA September 9, 2026

What changed: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 23, 2026.

Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVE-2026-20079 · Added by CISA September 9, 2026

What changed: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 12, 2026.

Adobe Commerce and Magento: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

CVE-2026-75650 · Added by CISA September 8, 2026

What changed: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

Why it matters: CISA includes vulnerabilities in this catalog when there is evidence they are being actively exploited. An affected internet-facing or business-critical system deserves prompt attention.

What to do: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. CISA remediation target: September 11, 2026.

Small-business action list

  • Ask your IT provider whether any affected product is in your environment.
  • Prioritize internet-facing, remote-access, identity, and backup systems.
  • Apply vendor updates or mitigations after appropriate testing.
  • Review privileged-account activity and confirm recoverable backups.

Verified source: CISA Known Exploited Vulnerabilities Catalog.

This edition is prepared automatically from CISA’s published data and provides general awareness, not an assessment of any specific organization.

AI + IT, under one roof

Build what is next.
Protect what matters.

Talk to ProTeamMSP