
CrowdSec
French open-source, crowdsourced cyber threat-intelligence and collaborative detection firm.
CrowdSec is a French crowdsourced threat-intelligence firm that spotted active exploitation of a FortiSandbox flaw on 17 June 2026, a month before CISA added it to its KEV catalogue.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Timeline for CrowdSec
Mentioned in: KEV patch clocks fell to three days
Cybersecurity: Threats and DefencesMentioned in: Arista, Fortinet and Cisco flaws listed
Cybersecurity: Threats and DefencesDetected in-the-wild exploitation of FortiSandbox on 17 June, a month before the KEV listing
Cybersecurity: Threats and Defences: CISA's KEV list runs a month lateBackground
CrowdSec is a French cyber threat-intelligence firm built on a crowdsourced, collaborative detection model: participating organisations share attack signals observed on their own networks, which CrowdSec aggregates to build a shared, real-time picture of active exploitation.
That model lets it often observe live exploitation before it is reflected in official government vulnerability catalogues, which typically depend on formal verification and coordination steps that take longer to complete.
Its network draws on telemetry contributed by participating organisations of many sizes, including some too small to run dedicated threat-intelligence operations of their own, which is part of why crowdsourced platforms like CrowdSec can sometimes spot live exploitation before centralised official catalogues formally list it.
CrowdSec caught the flaw a month early
CrowdSec detected hackers actively exploiting a flaw in Fortinet's FortiSandbox appliance, CVE-2026-39808, on 17 June 2026. CISA did not ADD that flaw to its official KEV catalogue until 16 July, leaving a month during which CrowdSec's own telemetry was ahead of the US government's public list.
The gap illustrates the role crowdsourced detection plays alongside official catalogues: organisations relying solely on KEV listing as a patch trigger had no signal on FortiSandbox for that entire month, even as exploitation was already under way.