“Immediately inventory all FortiOS and Cisco SD-WAN appliances across your client base, confirm patch levels, and verify that any FortiOS systems are patched beyond the bypass flaw — don't just check for the initial patch.”
Gunra Ransomware Group Actively Exploiting FortiOS VPN Flaws — CISA & FBI Joint Warning (August 12, 2026)
CISA and the FBI issued a joint advisory on 12 August 2026 warning that the Gunra ransomware group is actively leveraging known Fortinet VPN vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to forge persistent super-admin accounts with hard-coded passwords on compromised FortiGate devices. The campaign targets internet-facing FortiOS management interfaces and VPN endpoints to exfiltrate data and encrypt systems. Recommended actions: patch immediately, restrict internet-facing management access, enforce MFA, and audit for unauthorised local admin accounts.
Read more →CISA Adds FortiOS Patch-Bypass Flaw (CVE-2025-68686) to KEV — FCEB Deadline Was August 10, 2026
CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog, a FortiOS flaw that allows a remote unauthenticated attacker to bypass a previously issued patch via a symbolic-link persistence technique, provided they already have filesystem access from a prior compromise. Federal agencies had a patching deadline of 10 August 2026 under BOD 26-04; Australian MSPs should treat this as same-week priority for any internet-facing FortiOS appliance. Follow Fortinet's vendor guidance to apply the latest firmware and check for signs of prior compromise.
Read more →Cisco Catalyst SD-WAN Manager File-Write Flaw (CVE-2026-20262) Actively Exploited
Cisco disclosed that CVE-2026-20262 in Catalyst SD-WAN Manager is actively being exploited, allowing authenticated remote attackers to create or overwrite arbitrary files, leading to root privilege escalation. Organisations running Catalyst SD-WAN Manager should apply Cisco's patch and review affected systems for signs of unauthorised file creation. Limiting access to the SD-WAN Manager API to trusted networks is the recommended interim workaround.
Read more →Guardz AI-Native MSP Security Platform Bundles ITDR, EDR, Email Protection and Dark Web Monitoring
Guardz has positioned itself as an AI-native unified cybersecurity platform purpose-built for MSPs, integrating identity threat detection and response (ITDR), endpoint security (embedded SentinelOne EDR), email protection (powered by Check Point), cloud data protection, and dark web monitoring in a single multi-tenant platform. The consolidation play is aimed at MSPs struggling with alert fatigue across multiple point solutions, with MDR backing included. MSPs evaluating security stack consolidation should assess whether Guardz's integrated approach reduces operational overhead versus best-of-breed alternatives.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.