Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
62 articles · Updated July 15, 2026 -
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
A critical command injection vulnerability, CVE-2026-16812, has been discovered in the Arista VeloCloud Orchestrator On-Prem platform, allowing unauthenticated remote attackers to execute arbitrary commands. This flaw,…
23 articles · Updated July 28, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and…
6 articles · Updated July 22, 2026 -
Critical Vulnerabilities in FortiOS and Arista VeloCloud Under Active Exploitation
Fortinet's FortiOS and Arista's VeloCloud Orchestrator On-Prem are currently under attack due to critical vulnerabilities. The FortiOS vulnerability (CVE-2025-68686) allows unauthorized access to confidential…
2 articles · Updated July 28, 2026 -
State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits
Recent reports indicate a significant rise in the exploitation of edge devices, such as VPN gateways and firewalls, by state-sponsored actors. These devices have become the primary attack vector for espionage…
3 articles · Updated July 22, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously…
105 articles · Updated June 17, 2026 -
Critical RCE Vulnerabilities Discovered in Fortinet Products
Fortinet has identified multiple critical vulnerabilities in its FortiSandbox and FortiAuthenticator products, which could allow unauthenticated attackers to execute arbitrary code remotely. The vulnerabilities are…
107 articles · Updated May 12, 2026 -
Critical Vulnerabilities in Fortinet Products Allow Unauthorized Access
Fortinet has disclosed multiple vulnerabilities affecting its products, including FortiWeb, FortiManager, and FortiClientWindows. The most critical, CVE-2026-26035, allows remote unauthenticated access to FortiWeb…
2 articles · Updated August 14, 2026
Recent Intelligence Reports
- 004 — attack.mitre.org · August 20, 2026
- Fortinet FortiWeb: Attackers can log in with any credentials — Heise.De · August 14, 2026
- FG IR 26 161 — fortiguard.fortinet.com · August 13, 2026
- Fortinet Discloses Second Firewall Auth Bypass Patched In January — www.bleepingcomputer.com · August 12, 2026
- Cve 2024 55591 Fortinet Authentication Bypass Zero Day Vulnerability Exploited In The Wild — www.tenable.com · August 12, 2026
- CVE-2025-24472 — www.techtarget.com · August 12, 2026
- Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure — Infosecurity-Magazine · August 12, 2026
- Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA — Darkreading · August 11, 2026