CISA Flags Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Patch Deadline

CISA added Cisco, Citrix, and Fortinet flaws to its KEV catalog, requiring FCEB agencies to apply patches by September 12, 2026.

Bottom line: Apply patches to protect against CVE-2022-22715, CVE-2022-24447, and CVE-2022-25854 by September 12, 2026.

What's happening: CISA has cataloged the following vulnerabilities: CVE-2022-22715 (Cisco ASA 5506-X), CVE-2022-24447 (Citrix Hypervisor), and CVE-2022-25854 (Fortinet FortiGate 660D). The patches are available from Cisco, Citrix, and Fortinet, respectively.

What to do: Review your network configurations and ensure all FCEB agencies apply the patches by the deadline to mitigate the risks associated with these vulnerabilities.

Source: The Hacker News