In 30 seconds
- Your firewall, VPN, or remote access kit is now the fastest route into your business, and the people targeting it are not guessing. They are working from leaked credentials and known exploits.
- CISA (the US Cybersecurity and Infrastructure Security Agency) adding vulnerabilities to its KEV (Known Exploited Vulnerabilities) catalogue is a prioritisation signal, not a US government curiosity. If it is on KEV, assume it is being used, and assume you are late.
- Vendor advisories are increasingly about real world exploitation, not theoretical risk. If you treat them as background noise, you are choosing to be surprised.
Why it matters
There is a pattern here that regulated organisations cannot ignore. The attack surface that matters most is the one you expose to the internet, and the controls you rely on for access are being targeted relentlessly.
The NCSC has had to put out specific advice about Fortinet firewalls and VPN gateways being targeted globally. That is not a niche IT issue. In the Channel Islands, plenty of financial services firms, law firms, and public bodies run lean teams and depend on stable, long lived perimeter kit. The problem is that attackers also love stable, long lived perimeter kit, because it tends to be quietly forgotten once it is installed.
Then there is CISA and the KEV catalogue. For those unfamiliar, CISA is the United States Cybersecurity and Infrastructure Security Agency, the federal body responsible for coordinating national cyber defence. Their KEV catalogue, the Known Exploited Vulnerabilities list, is a public register of software flaws that are confirmed to be actively exploited in the wild. It is not a theoretical risk list. Every entry means someone, somewhere, is already using that vulnerability to break into organisations. The reason it matters outside the US is simple: attackers do not respect borders, and the same vulnerabilities being exploited in the US are being exploited everywhere else.
For a regulated business, KEV should translate into a simple rule. If it is on the list and it is relevant to your environment, it moves to the front of the queue, even if it is inconvenient.
Fortinet's own PSIRT advisories and the reporting around exploited FortiSandbox flaws are another reminder that security tooling is not automatically "safe". We buy these platforms to reduce risk, but they are still software, they still have bugs, and they still need patching and hardening like anything else.
Practical advice for this week:
- Treat internet facing remote access as "assume hostile". Reduce exposure, restrict by IP where you can, and monitor logins like you mean it.
- Stop relying on "we changed the password once". Rotate credentials on a schedule, and rotate immediately after any credible exposure.
- Run patching like a business process. Triage first, patch the high risk systems first, then mop up.
Questions to ask your team this week
- 1.Which internet facing systems do we have today (firewalls, VPNs, remote access portals, email gateways), and who is accountable for each one?
- 2.Are we actively monitoring admin logins and configuration changes on those edge systems, and can we evidence it for the last 30 days?
- 3.What is our process for acting on CISA KEV additions, and how quickly can we patch or mitigate when something relevant appears?
- 4.When did we last review whether management interfaces on edge devices are exposed to the internet, and whether MFA is enforced for every admin account?
One thing to do this week
Run a 30-minute "KEV and edge triage" session: pull your list of internet facing systems, check the last 30 days of vendor advisories against the CISA KEV catalogue, then assign owners and deadlines for patching or mitigation, starting with anything on the edge.
Sources
- UK NCSC, "Advice following global targeting of Fortinet firewalls and VPN gateways":
ncsc.gov.uk - CISA, Known Exploited Vulnerabilities Catalog:
cisa.gov - CISA, "CISA Adds One Known Exploited Vulnerability to Catalog" (1 July 2026):
cisa.gov - Fortinet PSIRT, FG-IR-26-141 (CVE-2026-25089):
fortiguard.fortinet.com - BleepingComputer, "Critical Fortinet FortiSandbox flaws now exploited in attacks":
bleepingcomputer.com

