#fortinet
5 articles
This archive covers seven articles from April 14 to May 13, 2026, focusing on Fortinet. The threat actor The Gentlemen was observed in these incidents. Key vulnerabilities include CVE-2025-59718, CVE-2026-21643, CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. The affected sectors are financial services, government, software consultancy, technology, and various others, with reports coming from Europe, North America, Turkey, and the UK. The severity mix across these articles is five critical and two high.
CRITICALCISA Adds Cisco CVE-2026-20079 With Perfect 10.0 Score to KEV
CISA's KEV catalog now lists CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco software, alongside exploited Citrix and Fortinet flaws. Federal patch deadline: Sept. 12.
CRITICALThe Gentlemen RaaS Internal Leak Exposes Admin, Affiliates, Tactics
A leaked backend database from The Gentlemen RaaS operation reveals 9 accounts, admin TOX ID, initial access via Fortinet/Cisco edge flaws, and a 190,000 USD ransom payout.
CRITICALFortiGate SSO Bypass CVE-2025-59718 Exploited in Active Attacks
Rapid7 IR confirms active exploitation of CVE-2025-59718 — a 9.8-CVSS FortiGate SSO bypass — enabling attackers to gain persistent admin access on unpatched appliances.
CRITICALPoC Exploit Released for Critical FortiSandbox Command Injection Flaw
A proof-of-concept exploit for CVE-2026-39808, a critical command injection vulnerability in Fortinet FortiSandbox, has been released. The flaw allows unauthenticated attackers to execute arbitrary OS commands as root.
HIGHCISA Flags Six Actively Exploited Flaws in Fortinet, Microsoft, Adobe
CISA added six vulnerabilities in Fortinet, Microsoft, and Adobe software to its Known Exploited Vulnerabilities catalog, warning of active in-the-wild attacks requiring urgent patching.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.