Signal
Attackers actively exploiting critical Fortinet and Cisco SD-WAN vulnerabilities
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-06-17 13:45 UTCUpdated 2026-06-17 15:42 UTC
rss
cveexploitssecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
In June 2026, attackers have been observed actively exploiting multiple critical vulnerabilities in Fortinet's FortiSandbox and Cisco's SD-WAN products.
Entities
FortinetCiscoFortiSandboxCisco Catalyst SD-WAN ValidatorSimo Kohonen
Score total
0.98
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- Exploitation of Fortinet vulnerabilities was first observed in early June 2026, shortly after patches were released.
- Cisco updated its advisory in June 2026 to include additional affected devices, highlighting ongoing risk.
- Recent detection of multiple exploitation events signals active threat campaigns targeting these flaws.
Why it matters
- These vulnerabilities allow attackers to gain persistent root access, threatening network security and data integrity.
- Widespread use of Fortinet and Cisco products means many organizations could be impacted.
- Exploitation activity indicates attackers are actively targeting critical infrastructure, increasing urgency for patching.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- Attackers are actively exploiting critical Fortinet FortiSandbox vulnerabilities disclosed in April 2026.
- Cisco updated its advisory to include Catalyst SD-WAN Validator as affected by the maximum-severity CVE-2026-20127 flaw allowing persistent root access.
How sources frame it
- CyberScoop: neutral
- The Register Security: neutral
This briefing highlights critical active exploits in widely deployed network security products, underscoring the need for immediate patching and monitoring.
All evidence
All evidence
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April
CyberScoop · cyberscoop.com · 2026-06-17 15:42 UTC
Cisco adds another SD-WAN box to max-severity bug advisory
The Register Security · theregister.com · 2026-06-17 13:45 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- CyberScoop (1)
- The Register Security (1)
Top origin domains (this list)
- cyberscoop.com (1)
- theregister.com (1)