VulnOps
2026-09-10Today's signals reveal four critical vulnerabilities spanning infrastructure and application layers: authentication bypasses in Citrix NetScaler and Cisco Firewall Management Center, a heap-based buffer overflow in Fortinet products, and an out-of-bounds write in Google Chromium V8. These represent high-priority assessment targets across network perimeter, management infrastructure, and browser-based attack surfaces.
- →CVE-2026-19490 & CVE-2026-20079: Dual Authentication Bypass in Critical Infrastructure: Authentication bypass vulnerabilities in NetScaler and Firewall Management Center directly compromise access controls on widely-deployed infrastructure, requiring immediate exploitation chain analysis and remediation prioritization.
- →CVE-2025-25249: Fortinet Heap-based Buffer Overflow: Heap overflow vulnerabilities in enterprise Fortinet products enable arbitrary code execution and require practitioners to assess exploitation feasibility and patch deployment timelines.
- →CVE-2026-87491: Chromium V8 Out-of-Bounds Write: Browser-based out-of-bounds write vulnerabilities create client-side exploitation vectors that practitioners must evaluate for targeted attack scenarios and user exposure assessment.
Prioritize vulnerability assessment for the two infrastructure authentication bypasses (NetScaler and Cisco FMC) and establish patch timelines for Fortinet and Chromium products based on your environment's exposure and attack surface risk.
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.