CISA Adds Cisco CVE-2026-20079 With Perfect 10.0 Score to KEV
CISA's KEV catalog now lists CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco software, alongside exploited Citrix and Fortinet flaws. Federal patch deadline: Sept. 12.

Executive Summary
CVE-2026-20079, an authentication bypass in Cisco software carrying a maximum CVSS score of 10.0, is among three actively exploited vulnerabilities the U.S. Cybersecurity and Infrastructure Security Agency added to its Known Exploited Vulnerabilities catalog on Wednesday. The other two affect Citrix and Fortinet products. Federal Civilian Executive Branch agencies must apply available patches by September 12, 2026 under Binding Operational Directive 22-01.
The 10.0 score places CVE-2026-20079 at the top of the severity scale — a rating typically reserved for remotely exploitable flaws requiring no authentication and yielding full system compromise. CISA's KEV inclusion confirms observed exploitation in the wild, not merely theoretical exploitability. Organizations running affected Cisco products should treat this as an emergency patch cycle regardless of whether they fall under the federal mandate.
Technical Analysis
CVE-2026-20079 is classified as an authentication bypass affecting Cisco software. The CVSS score of 10.0 indicates the maximum possible severity under the CVSS framework: network-exploitable, low complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. CISA's KEV entry does not specify the exact Cisco product or version range in the available source material, but the agency's decision to set a three-day remediation window signals that exploitation is either widespread or targeting high-value federal networks.
The two companion vulnerabilities affect Citrix and Fortinet products. CISA did not publicly detail the specific product versions or exploitation mechanics in the KEV addition itself. The Hacker News reported the three additions together, noting that each impacts a different vendor. The simultaneous KEV listing of flaws across three separate network infrastructure vendors — Cisco, Citrix, and Fortinet — is consistent with either coordinated exploitation campaigns targeting edge devices or independent actor activity that CISA aggregated into a single remediation directive.
All three vulnerabilities are subject to Binding Operational Directive 22-01, which requires FCEB agencies to remediate listed flaws within specified timeframes. The September 12 deadline gives agencies approximately three days from the Wednesday announcement — an unusually compressed window that reflects CISA's assessment of active exploitation risk.
CISA has not published the specific attack vectors, indicators of compromise, or threat actor attribution for any of the three flaws in the available source material. The agency's KEV catalog entry confirms exploitation but does not disclose whether the activity is attributed to a nation-state group, ransomware operation, or opportunistic scanning.
Mitigations & Recommendations
FCEB agencies must apply vendor patches for all three vulnerabilities by September 12, 2026. Private-sector organizations running Cisco, Citrix, or Fortinet products should verify whether their deployed versions are affected and prioritize patching accordingly.
Given the 10.0 CVSS score on CVE-2026-20079, defenders should assume that unpatched Cisco systems are fully compromisable by a remote, unauthenticated attacker. Network segmentation and monitoring for anomalous authentication events on Cisco management interfaces are warranted until patches are applied. For Citrix and Fortinet, the same urgency applies: these vendors' products sit at network perimeters and are frequently targeted by actors seeking initial access.
Organizations that cannot immediately patch should consider restricting management interface access to trusted IP ranges and enabling enhanced logging on the affected appliances. CISA's KEV catalog entry remains the authoritative source for updates on affected versions and any revised deadlines.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.
