Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fortinet security patch release for CVE-2026-39813

Security Patch Release
First reported
Last updated
Happening score
H score 41
2 unique sources, 2 articles

Summary

Hide ▲

Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three critical vulnerabilities that can enable unauthenticated privilege escalation and remote code execution. Administrators must upgrade affected deployments to the latest released versions to block incoming attacks.

Related Happenings

FortiBleed multi-vendor brute-force wave

Exploitation Wave
H score75 First: 23.06.2026 21:20 Last: 23.06.2026 21:20 Sources 1

About this happening: A multi-vendor brute-force wave tied to FortiBleed is hitting Fortinet, Synology, Sophos, Citrix, RDWeb, and MS-SQL targets, expanding the risk from one firewall-focus...

Fortinet FortiSandbox multi-CVE exploitation wave

Exploitation Wave
H score49 First: 16.06.2026 12:19 Last: 16.06.2026 12:19 Sources 1

How related: In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours.

About this happening: Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...

CISA KEV mitigation for LiteSpeed cPanel Plugin (CVE-2026-54420)

Advisory/Mitigation
H score38 First: 16.06.2026 08:41 Last: 16.06.2026 08:41 Sources 1

About this happening: CISA put CVE-2026-54420 in LiteSpeed cPanel Plugin on the KEV catalog, ordering FCEB agencies to apply fixes by June 18, 2026. The flaw is a CVSS 8.5 privile...

LiteSpeed cPanel user-end plugin urgent security update (CVE-2026-48172)

Security Patch Release
H score42 First: 27.05.2026 13:06 Last: 27.05.2026 13:06 Sources 1

About this happening: LiteSpeed released urgent security updates for the cPanel user-end plugin after CVE-2026-48172 was found to be actively exploited, reducing exposure for systems ru...

Latest development: 16.06.2026 13:47

CISA added CVE-2026-48172/CVE-2026-54420 in the LiteSpeed cPanel user-end plugin to the Known Exploited Vulnerabilities Catalog and ordered Federal Civilian Executive Branch agencies to secure affected servers within three days under BOD 26-04. The affected plugin versions before 2.4.8 are described as actively exploited, with FTP or web shell access enabling root escalation on shared hosting servers running CloudLinux/CageFS.

TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926

Security Patch Release
H score45 First: 22.05.2026 11:19 Last: 22.05.2026 11:19 Sources 1

About this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....

Timeline

  1. 16.06.2026 12:19 2 articles · 29d ago

    Fortinet releases FortiSandbox security updates for three critical flaws

    Mitigation Patch Update

    Fortinet released security updates for FortiSandbox on April 14 to address CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, three critical-severity flaws that can enable unauthenticated privilege escalation and remote code execution through low-complexity command injection with no user interaction. Administrators were instructed to upgrade affected deployments to the latest released versions to block incoming attacks.

    Show sources
  2. 16.06.2026 12:19 2 articles · 29d ago

    Defused observes active exploitation of Fortinet FortiSandbox vulnerabilities

    Exploitation Observed

    Defused said attackers were actively exploiting multiple Fortinet FortiSandbox vulnerabilities during the past 24 hours, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The firm noted that CVE-2026-39813 had no previous recorded exploitation and that a working exploit for CVE-2026-25089 had not yet been publicly disclosed.

    Show sources