<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network-Appliances on CuraSec</title><link>https://curasec.metacog.co.kr/tags/network-appliances/</link><description>Recent content in Network-Appliances on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 10 Sep 2026 14:58:06 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/network-appliances/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA KEV: Cisco, Citrix, Fortinet Flaws Actively Exploited, Patch by Sept 12</title><link>https://curasec.metacog.co.kr/insights/2026-09-10-cisa-flags-exploited-cisco-citrix-fortinet-flaws-sets-sept-1/</link><pubDate>Thu, 10 Sep 2026 14:58:06 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-10-cisa-flags-exploited-cisco-citrix-fortinet-flaws-sets-sept-1/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CVE-2026-20079 carries a CVSS 10.0, is KEV-listed, has a public PoC, and EPSS 0.75 — all three signal immediate exploitation pressure on Cisco, Citrix, and Fortinet devices common in enterprise perimeters; patch all three affected products to vendor-specified fixed versions before September 12.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of edge appliances from all three vendors means assume-breach posture is warranted — hunt for anomalous authentication events and lateral movement originating from Cisco, Citrix, and Fortinet devices since before today&amp;rsquo;s disclosure, and sweep for any available IOCs tied to these CVEs.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Three critical-severity, actively exploited flaws across widely deployed network vendors represent a systemic perimeter risk; confirm your team has prioritized patching all affected Cisco, Citrix, and Fortinet products before the Sept 12 deadline, and verify no prior compromise occurred on exposed appliances.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-20079 — CISA KEV: listed, EPSS 0.75, public PoC on GitHub, reported by 2 collected sources&lt;/li>
&lt;/ul></description></item></channel></rss>