Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Vulnerabilities Exploited by Hackers

Fortinet Vulnerabilities Exploited by Hackers

Posted on June 17, 2026 By CWS

Several vulnerabilities recently patched in Fortinet’s FortiSandbox are being actively targeted by cybercriminals, according to security firm Defused. These vulnerabilities, identified as CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089, have been observed in hacking attempts worldwide.

Critical Vulnerabilities Targeted

Defused has recorded exploitation attempts of these vulnerabilities through their honeypots. Both CVE-2026-39813 and CVE-2026-39808 were classified as ‘critical severity’ and received patches in April. The first allows attackers to bypass authentication, while the latter involves OS command injection, enabling the execution of arbitrary code.

Fortinet addressed CVE-2026-25089 in their June 2026 updates. This flaw allows remote attackers to execute commands without authentication. Notably, the vulnerability CVE-2026-39808 was independently exploited, as reported by KEVIntel on June 12, with subsequent attacks on CVE-2026-39813 detected by both firms on June 15.

Emerging Threats and Exploits

Interestingly, the exploit technique for CVE-2026-25089 appears to have been AI-generated, though initially ineffective, according to Defused. Additionally, vulnerabilities in Fortinet FortiClient EMS, specifically CVE-2026-21643 and CVE-2026-35616, have also been exploited recently.

In a separate incident, SOCRadar uncovered a large-scale compromise of Fortinet firewalls, affecting over 30,000 devices globally. Named ‘FortiBleed,’ this campaign exposes corporate networks to potential risks through systematic attacks on Fortinet firewalls and VPN gateways.

Impact and Ongoing Risks

SOCRadar’s findings reveal that the compromised devices belong to various organizations across more than 190 countries, with significant numbers in both India and the United States. Attackers are reportedly using a curated list of passwords to gain access, monitoring traffic, and collecting additional credentials for further exploitation.

Researchers were able to gather insights into the attacker’s operations due to an exposed server, uncovering credentials linked to a defense industry VPN endpoint. This suggests the attackers’ intentions might extend beyond financial motives.

While attribution remains uncertain, there is speculation about the involvement of Russian-speaking hackers. As these threats evolve, organizations are urged to update security measures and patch vulnerabilities promptly to safeguard their networks.

Security Week News Tags:CVE, Cybersecurity, Defused, Exploitation, Firewalls, FortiBleed, FortiClient, Fortinet, FortiSandbox, Hacking, KEVIntel, Patch, SOCRadar, VPN, Vulnerabilities

Post navigation

Previous Post: Joomla JCE Vulnerability Exploited for PHP Code Execution
Next Post: AIRecon Revolutionizes Offline Penetration Testing

Related Posts

DDoS Attacks Blocked by Cloudflare in 2025 Already Surpass 2024 Total  DDoS Attacks Blocked by Cloudflare in 2025 Already Surpass 2024 Total  Security Week News
Webinar Today: Protecting What WAFs and Gateways Can’t See – Register Webinar Today: Protecting What WAFs and Gateways Can’t See – Register Security Week News
The Congressional Budget Office Was Hacked. It Says It Has Implemented New Security Measures The Congressional Budget Office Was Hacked. It Says It Has Implemented New Security Measures Security Week News
Marquis Data Breach Impacts 672,000 Individuals Marquis Data Breach Impacts 672,000 Individuals Security Week News
Trent AI Launches with M Seed Funding Boost Trent AI Launches with $13M Seed Funding Boost Security Week News
SailPoint’s GitHub Repositories Breached in Security Incident SailPoint’s GitHub Repositories Breached in Security Incident Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking
  • Top DNS Security Solutions for 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark