Attackers Hit Pair of Critical Fortinet Vulnerabilities the Vendor Disclosed in April
ID: 3efa4b9e-96ad-5c11-8bfa-37603458a7e2
STIX ID: report--3efa4b9e-96ad-5c11-8bfa-37603458a7e2
Feed Name: CosmicBytez Labs
Critical remote-code-execution vulnerabilities in Fortinet FortiSandbox disclosed in April 2026 are being actively exploited by multiple distinct threat actors, with exploitation confirmed by firms including CrowdStrike and Mandiant; unpatched, widely deployed instances (SOCs, MSSPs, finance, government, healthcare) are at immediate risk and should be identified and patched or taken offline. The report highlights the high value of a compromised sandbox for pivoting and intelligence collection, documents a recurring Fortinet patching/exploitation pattern, and provides immediate, short-term, and ongoing mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
