Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April

2026-06-18T14:51:40Zbb7eabc45f9222d5e350dea6fe4944fc262022eea7ab19d0ba719ea410a35460
active-exploitationcriticalfortinetfortisandboxmultiple-actorsnetwork-securitypatchingsandboxvulnerability

What happened

Multiple security firms have observed active exploitation of two critical FortiSandbox vulnerabilities that Fortinet disclosed in April. Observations indicate attacks are coming from multiple, distinct actors rather than a single campaign. Organizations using FortiSandbox should assume active exploitation, prioritize applying vendor patches and mitigations, and monitor for related indicators of compromise.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
bb7eabc45f9222d5e350dea6fe4944fc262022eea7ab19d0ba719ea410a35460
Enrichment time
2026-06-18T14:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April · Baitaphish