🔥 この記事の詳細
2026-09-11 更新
B
今週中

米CISAは、Ciscoのファイアウォール管理製品やFortinetのFortiOS、CitrixのNetScalerなどの脆弱性4件が実際に悪用されているとし…

脆弱性📰 2記事🌐 2 countries
🇯🇵 Japan · 🇺🇸 US
🖥️ 製品FortiOSNetScaler
🔢 CVECVE-2026-20079CVE-2025-25249
📅 2026-09-11📰 secnext
📌 一言でいうと
CISAは、Ciscoのファイアウォール管理製品やFortinetのFortiOS、CitrixのNetScalerなどの脆弱性4件が実際に悪用されているとして、KEVカタログに追加しました。特にCVE-2026-20079は認証回避によるroot権限取得が可能であり、CVE-2025-25249はリモートでのコード実行が可能な深刻な脆弱性です。影響を受ける製品を利用している組織は、速やかに最新のセキュリティパッチを適用することが推奨されます。
🔍該当判定
  • Ciscoのファイアウォール管理ソフト「Secure Firewall Management Center (FMC)」またはクラウドサービスの「Security Cloud Control (SCC)」を利用している
  • Fortinet社の「FortiOS」を搭載した製品(FortiGateなど)を利用している
  • Fortinet社の「FortiSwitchManager」を利用している
  • Citrix社の「NetScaler」を利用している
上記いずれにも該当しない → 静観でOK
該当時の対応
影響を受ける製品(Cisco FMC/SCC, FortiOS, FortiSwitchManager, NetScaler等)の最新バージョンへのアップデートを適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Cisco, Fortinet, Citrix製品の悪用済み脆弱性への対応について

お疲れさまです。CISAのKEVカタログに新たな脆弱性が追加された件について情報共有です。

■ 概要
Cisco、Fortinet、Citrixの製品における脆弱性が実際に悪用されていることが確認されました。認証回避によるroot権限奪取や、リモートでのコード実行が可能な深刻な内容です。

■ 影響範囲
- Cisco Secure Firewall Management Center (FMC) / Security Cloud Control (SCC)
- FortiOS / FortiSwitchManager 等のFortinet製品
- Citrix NetScaler

■ 対応手順
1. 自社環境で上記製品の利用有無およびバージョンを確認してください。
2. 各ベンダーが公開している最新のセキュリティパッチを適用してください。

■ 参考情報
- CISA Known Exploited Vulnerabilities Catalog
- 各ベンダー公式セキュリティアドバイザリ

対応優先度: 高
対応期限: 速やかに
Subject: [Urgent] Remediation for Exploited Vulnerabilities in Cisco, Fortinet, and Citrix Products

Dear Team,

This is to notify you that CISA has added four vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog.

■ Overview
Active exploitation has been confirmed for vulnerabilities in Cisco, Fortinet, and Citrix products. These include critical flaws allowing authentication bypass for root access and remote code execution (RCE).

■ Affected Scope
- Cisco Secure Firewall Management Center (FMC) / Security Cloud Control (SCC)
- Fortinet products including FortiOS and FortiSwitchManager
- Citrix NetScaler

■ Action Plan
1. Identify if the affected products and versions are deployed within our environment.
2. Apply the latest security patches provided by the respective vendors immediately.

■ Reference
- CISA Known Exploited Vulnerabilities Catalog
- Official Vendor Security Advisories

Priority: High
Deadline: Immediate