Signal

Attackers actively exploiting critical Fortinet and Cisco SD-WAN vulnerabilities

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-17 13:45 UTCUpdated 2026-06-17 15:42 UTC
rss
cveexploitssecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Cisco adds another SD-WAN box to max-severity bug advisory
The Register Security · News · theregister.com · 2026-06-17 13:45 UTC
limited source diversity in top sources
Overview

In June 2026, attackers have been observed actively exploiting multiple critical vulnerabilities in Fortinet's FortiSandbox and Cisco's SD-WAN products.

Entities
FortinetCiscoFortiSandboxCisco Catalyst SD-WAN ValidatorSimo Kohonen
Score total
0.98
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Exploitation of Fortinet vulnerabilities was first observed in early June 2026, shortly after patches were released.
  • Cisco updated its advisory in June 2026 to include additional affected devices, highlighting ongoing risk.
  • Recent detection of multiple exploitation events signals active threat campaigns targeting these flaws.
Why it matters
  • These vulnerabilities allow attackers to gain persistent root access, threatening network security and data integrity.
  • Widespread use of Fortinet and Cisco products means many organizations could be impacted.
  • Exploitation activity indicates attackers are actively targeting critical infrastructure, increasing urgency for patching.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • Attackers are actively exploiting critical Fortinet FortiSandbox vulnerabilities disclosed in April 2026.
  • Cisco updated its advisory to include Catalyst SD-WAN Validator as affected by the maximum-severity CVE-2026-20127 flaw allowing persistent root access.
How sources frame it
  • CyberScoop: neutral
  • The Register Security: neutral
This briefing highlights critical active exploits in widely deployed network security products, underscoring the need for immediate patching and monitoring.
All evidence
All evidence
Cisco adds another SD-WAN box to max-severity bug advisory
The Register Security · theregister.com · 2026-06-17 13:45 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • CyberScoop (1)
  • The Register Security (1)
Top origin domains (this list)
  • cyberscoop.com (1)
  • theregister.com (1)