Security · Sep 11
CISA KEV Catalog Update Puts Cisco, Citrix, and Fortinet on a September 12, 2026 Patch Clock
Three exploited network flaws show why KEV status is not just another scanner finding, it is triage with a timer.
- Treat KEV entries as patch priorities because CISA has confirmed real exploitation.
- Use vendor advisories, exposure, and due dates together, not CVSS alone.
- After patching, verify the fix and check logs for possible earlier exploitation.